Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

25,946 CVEs affect a tracked app or OS (all severities, all platforms). 373 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
25,946
Actively exploited
373
Publication window
1997-01-01 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

25,946 entries
CVE
CVE-2026-72945
MEDIUM 5.5

Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.

CVE-2026-72944
HIGH 7.8

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72943
HIGH 7.5

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

CVE-2026-72942
MEDIUM 6.5

Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.

CVE-2026-72941
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72940
HIGH 8.8

Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network.

CVE-2026-72939
MEDIUM 6.5

Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.

CVE-2026-72937
MEDIUM 5.5

Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.

CVE-2026-72936
HIGH 8.1

Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network.

CVE-2026-72935
MEDIUM 6.7

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-72933
HIGH 8.8

Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.

CVE-2026-72932
HIGH 7.5

Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.

CVE-2026-72931
MEDIUM 4.7

Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.

CVE-2026-72930
HIGH 7.0

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.

CVE-2026-72929
HIGH 7.8

Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-72928
HIGH 7.5

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

CVE-2026-72927
MEDIUM 6.7

Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.

CVE-2026-72926
HIGH 7.0

Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.

CVE-2026-71353
HIGH 7.0

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-71352
HIGH 8.8

Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.

CVE-2026-71351
HIGH 7.0

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-71350
MEDIUM 6.8

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-71349
MEDIUM 6.8

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-71348
MEDIUM 6.8

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-71345
HIGH 7.8

Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.

CVE-2026-71343
HIGH 7.8

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.

CVE-2026-71342
HIGH 7.0

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-71341
MEDIUM 5.5

Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.

CVE-2026-71340
HIGH 7.0

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

CVE-2026-71339
MEDIUM 6.7

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-71338
MEDIUM 6.4

Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.

CVE-2026-71337
HIGH 7.8

Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

CVE-2026-71336
HIGH 8.8

Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.

CVE-2026-71334
HIGH 7.8

Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.

CVE-2026-71333
HIGH 7.0

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-71332
HIGH 7.0

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.

CVE-2026-71330
HIGH 7.5

Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to dis…

CVE-2026-71329
MEDIUM 6.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-70587
HIGH 7.5

Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

CVE-2026-70586
HIGH 8.8

Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.

CVE-2026-70585
HIGH 7.0

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.

CVE-2026-70584
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

CVE-2026-70583
HIGH 7.8

Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

CVE-2026-70582
MEDIUM 6.4

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker…

CVE-2026-70581
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70579
HIGH 7.5

Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.

CVE-2026-70578
HIGH 7.0

Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.

CVE-2026-70577
HIGH 7.0

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVE-2026-70575
MEDIUM 5.3

Null pointer dereference in Windows Schannel allows an authorized attacker to deny service over a network.

CVE-2026-70574
HIGH 7.8

Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM