Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,601 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,601
Actively exploited
294
Publication window
2004-07-27 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,601 entries High Clear all
CVE
CVE-2026-61359
HIGH 7.8

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-61358
HIGH 7.8

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate …

CVE-2026-61357
HIGH 7.8

Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.

CVE-2026-61356
HIGH 7.8

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-61355
HIGH 7.8

Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVE-2026-61353
HIGH 7.8

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-61352
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute…

CVE-2026-61349
HIGH 7.8

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

CVE-2026-61348
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-61346
HIGH 7.0

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-59134
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-59132
HIGH 7.5

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

CVE-2026-59127
HIGH 7.8

Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-59126
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to e…

CVE-2026-59125
HIGH 7.0

Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-59122
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-56179
HIGH 8.3

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVE-2026-56174
HIGH 7.8

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVE-2026-54984
HIGH 7.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

CVE-2026-54113
HIGH 7.5

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.

CVE-2026-50472
HIGH 7.0

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

CVE-2026-49179
HIGH 8.8

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code…

CVE-2026-42976
HIGH 7.8

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.

CVE-2026-6726
HIGH 7.9

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a cred…

CVE-2026-49746
HIGH 7.1

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU…

CVE-2026-62918
HIGH 7.5

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-19177
HIGH 8.3

Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to…

CVE-2026-19176
HIGH 7.5

Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code in…

CVE-2026-19174
HIGH 8.8

Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (…

CVE-2026-19173
HIGH 8.3

Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform …

CVE-2026-19172
HIGH 8.3

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sa…

CVE-2026-19169
HIGH 8.8

Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalati…

CVE-2026-19168
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

CVE-2026-19165
HIGH 7.5

Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to execute arbi…

CVE-2026-19163
HIGH 8.3

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially p…

CVE-2026-19162
HIGH 8.8

Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page…

CVE-2026-19159
HIGH 7.5

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentiall…

CVE-2026-19158
HIGH 7.5

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to…

CVE-2026-19156
HIGH 7.5

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially …

CVE-2026-19155
HIGH 8.3

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a…

CVE-2026-19154
HIGH 8.3

Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially pe…

CVE-2026-19153
HIGH 8.1

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer proce…

CVE-2026-19152
HIGH 8.3

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to po…

CVE-2026-19151
HIGH 8.8

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…

CVE-2026-19150
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

CVE-2026-19148
HIGH 8.3

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially …

CVE-2026-19147
HIGH 8.3

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perf…

CVE-2026-19145
HIGH 8.8

Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pa…

CVE-2026-19144
HIGH 8.8

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro…

CVE-2026-19143
HIGH 8.6

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a san…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM