Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

25,946 CVEs affect a tracked app or OS (all severities, all platforms). 373 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
25,946
Actively exploited
373
Publication window
1997-01-01 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

25,946 entries
CVE
CVE-2026-69671
HIGH 8.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-69669
HIGH 8.8

Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network.

CVE-2026-69654
HIGH 7.0

Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.

CVE-2026-69652
HIGH 7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69648
HIGH 7.0

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

CVE-2026-69645
HIGH 7.0

Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

CVE-2026-69643
HIGH 8.0

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.

CVE-2026-69638
HIGH 8.4

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-69637
MEDIUM 5.7

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

CVE-2026-69631
HIGH 7.5

Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network.

CVE-2026-69630
HIGH 7.0

Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69629
HIGH 8.8

Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

CVE-2026-69628
HIGH 8.8

Heap-based buffer overflow in Windows iSCSI allows an authorized attacker to execute code over a network.

CVE-2026-69627
MEDIUM 5.5

Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.

CVE-2026-69625
HIGH 8.0

Heap-based buffer overflow in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges over a network.

CVE-2026-69624
MEDIUM 6.5

Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.

CVE-2026-69623
HIGH 8.0

Heap-based buffer overflow in Windows HTTP Print Provider allows an authorized attacker to execute code over a network.

CVE-2026-69621
HIGH 7.0

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69620
HIGH 8.1

Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-69619
HIGH 8.0

Out-of-bounds read in Windows exFAT File System allows an authorized attacker to elevate privileges over a network.

CVE-2026-69618
MEDIUM 5.5

Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally.

CVE-2026-69617
HIGH 7.0

Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-69616
MEDIUM 5.5

Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally.

CVE-2026-69613
HIGH 7.0

Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

CVE-2026-69612
HIGH 7.8

Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69611
HIGH 7.0

Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69610
HIGH 7.0

Buffer over-read in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69609
MEDIUM 5.5

Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-69608
HIGH 7.8

Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69607
HIGH 7.5

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

CVE-2026-69606
HIGH 7.0

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

CVE-2026-69605
HIGH 7.0

Use after free in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69604
HIGH 7.8

Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69603
HIGH 8.8

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

CVE-2026-69602
HIGH 7.1

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network.

CVE-2026-69601
HIGH 8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-69600
HIGH 7.0

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69599
HIGH 7.5

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-69598
HIGH 8.8

Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.

CVE-2026-69597
HIGH 7.1

Use after free in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

CVE-2026-69595
CRITICAL 9.8

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-69594
HIGH 7.8

Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.

CVE-2026-69593
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69592
HIGH 7.8

Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-69591
MEDIUM 5.7

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network.

CVE-2026-69590
CRITICAL 9.8

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-69589
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69588
HIGH 7.5

Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

CVE-2026-69587
HIGH 7.5

Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.

CVE-2026-69586
CRITICAL 9.8

Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM