Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

25,946 CVEs affect a tracked app or OS (all severities, all platforms). 373 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
25,946
Actively exploited
373
Publication window
1997-01-01 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

25,946 entries
CVE
CVE-2026-73005
HIGH 7.0

Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

CVE-2026-73004
MEDIUM 5.5

Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally.

CVE-2026-73003
HIGH 7.0

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVE-2026-73002
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73001
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73000
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72999
MEDIUM 6.8

Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-72997
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72996
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72995
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72994
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72993
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72992
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72991
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72990
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72989
HIGH 7.5

Use of uninitialized resource in Windows Failover Cluster allows an unauthorized attacker to disclose information over a network.

CVE-2026-72988
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72987
HIGH 8.1

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-72986
HIGH 8.8

Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.

CVE-2026-72985
MEDIUM 6.8

Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-72983
CRITICAL 9.8

Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.

CVE-2026-72982
CRITICAL 9.8

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

CVE-2026-72981
HIGH 8.1

Use after free in IP Helper allows an unauthorized attacker to execute code over a network.

CVE-2026-72980
MEDIUM 4.4

Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.

CVE-2026-72979
CRITICAL 9.8

Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-72978
MEDIUM 5.9

Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a net…

CVE-2026-72977
MEDIUM 6.5

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

CVE-2026-72976
MEDIUM 5.0

Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.

CVE-2026-72975
MEDIUM 6.5

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

CVE-2026-72973
HIGH 8.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-72972
HIGH 8.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-72967
HIGH 7.8

Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

CVE-2026-72966
MEDIUM 5.5

Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.

CVE-2026-72965
HIGH 7.8

Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72964
MEDIUM 5.5

Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.

CVE-2026-72963
HIGH 7.0

Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.

CVE-2026-72962
HIGH 8.2

Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-72961
HIGH 8.2

Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

CVE-2026-72960
HIGH 8.8

Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

CVE-2026-72959
HIGH 8.8

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-72958
HIGH 8.2

Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.

CVE-2026-72957
HIGH 7.8

Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.

CVE-2026-72954
HIGH 7.5

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

CVE-2026-72953
HIGH 7.8

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-72952
HIGH 7.0

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.

CVE-2026-72950
HIGH 8.8

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-72949
HIGH 7.5

Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.

CVE-2026-72948
MEDIUM 6.7

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-72947
MEDIUM 6.4

Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72946
HIGH 7.8

Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM