Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,602 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,602
Actively exploited
294
Publication window
2004-07-27 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,602 entries High Clear all
CVE
CVE-2026-68807
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-68806
HIGH 7.8

Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-68805
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-68804
HIGH 7.8

Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-68803
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-68801
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-68800
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-68796
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-68795
HIGH 7.8

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-68794
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-68793
HIGH 7.8

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-66804
HIGH 7.8

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

CVE-2026-66802
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized a…

CVE-2026-66799
HIGH 7.8

Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.

CVE-2026-65814
HIGH 7.8

Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-65807
HIGH 8.8

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

CVE-2026-65796
HIGH 8.1

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

CVE-2026-65790
HIGH 7.8

Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

CVE-2026-65789
HIGH 8.1

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-65788
HIGH 7.0

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-65787
HIGH 7.8

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-65786
HIGH 7.8

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-65783
HIGH 7.0

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

CVE-2026-65782
HIGH 7.0

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

CVE-2026-65781
HIGH 7.0

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

CVE-2026-65780
HIGH 7.0

Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

CVE-2026-65779
HIGH 7.0

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

CVE-2026-65778
HIGH 7.0

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

CVE-2026-65776
HIGH 7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-65775
HIGH 7.8

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-65774
HIGH 7.8

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-65773
HIGH 7.8

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-65681
HIGH 7.5

Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.

CVE-2026-65679
HIGH 8.1

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

CVE-2026-65678
HIGH 7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-65672
HIGH 7.8

Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.

CVE-2026-65671
HIGH 7.8

Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.

CVE-2026-64915
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-64907
HIGH 7.8

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-64905
HIGH 7.8

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-63527
HIGH 7.8

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-63525
HIGH 7.8

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-63518
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-62908
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate p…

CVE-2026-62894
HIGH 7.8

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-62892
HIGH 7.0

Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

CVE-2026-62890
HIGH 7.8

Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.

CVE-2026-62889
HIGH 8.1

Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

CVE-2026-62888
HIGH 7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-62885
HIGH 7.8

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM