Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,433 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,433
Actively exploited
21
Publication window
2009-07-30 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,433 entries Medium Windows Clear all
CVE
CVE-2026-12322
MEDIUM 5.4

Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12321
MEDIUM 5.4

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12320
MEDIUM 4.3

Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12319
MEDIUM 6.5

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12313
MEDIUM 4.7

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderb…

CVE-2026-12311
MEDIUM 4.7

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderb…

CVE-2026-12309
MEDIUM 6.5

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12308
MEDIUM 5.3

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12307
MEDIUM 5.3

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12306
MEDIUM 5.3

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12303
MEDIUM 4.3

Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12302
MEDIUM 6.5

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thu…

CVE-2026-12301
MEDIUM 5.3

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12300
MEDIUM 5.3

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12299
MEDIUM 5.4

JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and…

CVE-2026-12298
MEDIUM 5.4

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12033
MEDIUM 5.3

Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain potentially…

CVE-2026-12026
MEDIUM 6.5

Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain p…

CVE-2026-12025
MEDIUM 5.3

Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer proce…

CVE-2026-12024
MEDIUM 6.5

Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass same origin policy via a crafted HTML …

CVE-2026-12015
MEDIUM 5.3

Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially se…

CVE-2026-50508
MEDIUM 6.5

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-50507
MEDIUM 6.8

Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-48566
MEDIUM 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-45655
MEDIUM 5.3

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-45634
MEDIUM 5.5

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

CVE-2026-45608
MEDIUM 6.8

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

CVE-2026-45606
MEDIUM 5.5

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

CVE-2026-45604
MEDIUM 5.5

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

CVE-2026-45595
MEDIUM 5.4

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-45594
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informat…

CVE-2026-44814
MEDIUM 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVE-2026-44805
MEDIUM 5.5

Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.

CVE-2026-42973
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42972
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.

CVE-2026-42971
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42970
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42969
MEDIUM 5.5

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42968
MEDIUM 5.5

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.

CVE-2026-42915
MEDIUM 5.5

Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.

CVE-2026-42914
MEDIUM 5.3

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

CVE-2026-42907
MEDIUM 6.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

CVE-2026-42906
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

CVE-2026-42903
MEDIUM 6.5

Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.

CVE-2026-11701
MEDIUM 5.4

Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (…

CVE-2026-11696
MEDIUM 5.3

Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain pot…

CVE-2026-11695
MEDIUM 4.3

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page.…

CVE-2026-11685
MEDIUM 4.3

Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted …

CVE-2026-11678
MEDIUM 5.3

Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially se…

CVE-2026-11669
MEDIUM 5.3

Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain p…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM