Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

25,946 CVEs affect a tracked app or OS (all severities, all platforms). 373 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
25,946
Actively exploited
373
Publication window
1997-01-01 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

25,946 entries
CVE
CVE-2026-70573
HIGH 7.0

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70572
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70570
HIGH 7.5

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-70569
HIGH 7.8

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-70568
HIGH 7.0

Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70567
HIGH 7.0

Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70565
HIGH 7.0

Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.

CVE-2026-70564
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-70563
HIGH 8.1

Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-70562
HIGH 7.0

Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70342
HIGH 8.1

Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-70296
CRITICAL 9.8

Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-70290
MEDIUM 5.5

Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.

CVE-2026-70289
HIGH 7.8

Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

CVE-2026-70283
HIGH 7.0

Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-70203
HIGH 8.8

Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

CVE-2026-70145
MEDIUM 5.5

Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

CVE-2026-70124
MEDIUM 5.9

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

CVE-2026-70091
MEDIUM 5.9

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over…

CVE-2026-70065
HIGH 7.5

Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-70019
MEDIUM 6.5

Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network.

CVE-2026-69989
HIGH 8.1

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

CVE-2026-69930
MEDIUM 5.9

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

CVE-2026-69929
MEDIUM 5.9

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

CVE-2026-69921
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-69911
HIGH 7.0

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69910
CRITICAL 9.8

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

CVE-2026-69907
HIGH 7.8

Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.

CVE-2026-69906
HIGH 8.2

Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-69900
HIGH 7.8

Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69896
HIGH 7.0

Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69895
MEDIUM 4.7

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

CVE-2026-69891
HIGH 7.0

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-69890
HIGH 7.5

Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.

CVE-2026-69889
HIGH 7.0

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69881
HIGH 7.5

Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.

CVE-2026-69878
MEDIUM 6.4

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code locally.

CVE-2026-69876
HIGH 8.0

Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.

CVE-2026-69875
HIGH 8.0

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69874
HIGH 8.2

Untrusted pointer dereference in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVE-2026-69866
HIGH 7.0

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69864
HIGH 7.8

Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.

CVE-2026-69862
MEDIUM 5.5

Out-of-bounds read in Windows Wireless Wide Area Network Service allows an authorized attacker to disclose information locally.

CVE-2026-69860
HIGH 8.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-69859
HIGH 7.0

Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69858
HIGH 8.1

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-69853
MEDIUM 4.7

Use of uninitialized resource in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-69852
HIGH 7.5

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-69847
HIGH 8.0

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.

CVE-2026-69846
HIGH 8.2

Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM