Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

25,946 CVEs affect a tracked app or OS (all severities, all platforms). 373 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
25,946
Actively exploited
373
Publication window
1997-01-01 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

25,946 entries
CVE
CVE-2026-69761
HIGH 7.1

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.

CVE-2026-69760
HIGH 7.5

Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network.

CVE-2026-69759
HIGH 8.8

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-69758
HIGH 7.8

Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-69757
HIGH 7.1

Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges over a network.

CVE-2026-69744
HIGH 7.5

Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.

CVE-2026-69741
MEDIUM 5.5

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.

CVE-2026-69740
HIGH 8.8

Use after free in Windows Hello allows an authorized attacker to elevate privileges locally.

CVE-2026-69738
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69735
HIGH 7.0

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69734
MEDIUM 6.5

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-69732
HIGH 8.1

Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.

CVE-2026-69731
HIGH 7.8

Heap-based buffer overflow in HID class driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69730
CRITICAL 9.8

Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

CVE-2026-69729
HIGH 8.8

Heap-based buffer overflow in Windows Credential Providers allows an authorized attacker to execute code over a network.

CVE-2026-69727
HIGH 8.0

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69725
HIGH 7.8

Double free in Windows Hello allows an authorized attacker to elevate privileges locally.

CVE-2026-69723
MEDIUM 5.7

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a netwo…

CVE-2026-69722
HIGH 8.8

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-69720
HIGH 7.8

Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVE-2026-69719
MEDIUM 6.5

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

CVE-2026-69717
HIGH 8.0

Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.

CVE-2026-69715
CRITICAL 9.8

Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.

CVE-2026-69714
HIGH 8.0

Stack-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69713
MEDIUM 4.4

Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-69712
HIGH 8.8

Use after free in Windows Key Distribution Center allows an authorized attacker to execute code over a network.

CVE-2026-69711
HIGH 7.0

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69710
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privilege…

CVE-2026-69709
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-69708
HIGH 7.0

Use after free in Windows Web Platform Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-69707
HIGH 7.8

Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69706
HIGH 7.1

Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.

CVE-2026-69694
HIGH 7.0

Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69693
HIGH 7.0

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

CVE-2026-69692
HIGH 7.0

Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69691
HIGH 7.8

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-69689
HIGH 8.0

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges over a network.

CVE-2026-69688
HIGH 7.1

Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network.

CVE-2026-69687
HIGH 7.8

Integer underflow (wrap or wraparound) in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69686
HIGH 8.8

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-69685
HIGH 7.8

Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

CVE-2026-69684
MEDIUM 5.5

Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.

CVE-2026-69682
HIGH 7.0

Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69681
HIGH 8.0

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges over a network.

CVE-2026-69680
HIGH 8.1

Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-69679
MEDIUM 5.7

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

CVE-2026-69678
HIGH 8.8

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.

CVE-2026-69676
HIGH 8.8

Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.

CVE-2026-69674
MEDIUM 5.5

Missing authentication for critical function in Windows Modern Device Management (MDM) allows an authorized attacker to bypass a security feature locally.

CVE-2026-69672
MEDIUM 5.5

Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM