Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

25,946 CVEs affect a tracked app or OS (all severities, all platforms). 373 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
25,946
Actively exploited
373
Publication window
1997-01-01 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

25,946 entries
CVE
CVE-2026-69585
HIGH 7.8

Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69584
HIGH 7.8

Integer overflow or wraparound in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69583
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69582
HIGH 7.8

Buffer over-read in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69581
HIGH 7.0

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69580
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69579
CRITICAL 9.8

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

CVE-2026-69578
HIGH 7.0

Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-69576
HIGH 7.8

Use after free in Graphic Fonts allows an authorized attacker to elevate privileges locally.

CVE-2026-69575
HIGH 7.0

Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

CVE-2026-69574
HIGH 7.0

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69573
HIGH 7.0

Use after free in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-69572
MEDIUM 5.7

Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network.

CVE-2026-69571
HIGH 7.8

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69569
MEDIUM 5.7

Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network.

CVE-2026-69568
MEDIUM 5.5

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally.

CVE-2026-69567
HIGH 7.0

Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-69566
MEDIUM 6.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-69564
HIGH 7.0

Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.

CVE-2026-69563
HIGH 7.0

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69561
HIGH 7.8

Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69560
HIGH 7.0

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69556
HIGH 8.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-69554
MEDIUM 5.5

Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.

CVE-2026-69553
HIGH 7.1

Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.

CVE-2026-69552
MEDIUM 5.7

Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a n…

CVE-2026-69551
HIGH 8.8

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

CVE-2026-69549
HIGH 7.0

Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69548
MEDIUM 4.6

Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-69547
HIGH 8.8

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

CVE-2026-69546
HIGH 8.1

Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

CVE-2026-69544
HIGH 7.8

Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.

CVE-2026-69542
HIGH 7.8

Heap-based buffer overflow in Windows Camera Frame Server Monitor allows an authorized attacker to elevate privileges locally.

CVE-2026-69541
HIGH 7.8

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69540
HIGH 7.0

Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69539
HIGH 7.5

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-69538
HIGH 7.8

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.

CVE-2026-69536
HIGH 7.1

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-69535
HIGH 7.8

Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-69534
HIGH 7.8

Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized att…

CVE-2026-69532
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-69531
MEDIUM 5.5

Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.

CVE-2026-69530
HIGH 8.1

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

CVE-2026-69528
HIGH 7.8

Missing authentication for critical function in Windows Shell allows an authorized attacker to elevate privileges locally.

CVE-2026-69527
MEDIUM 5.5

Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally.

CVE-2026-69525
CRITICAL 9.8

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

CVE-2026-69524
HIGH 8.1

Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

CVE-2026-69518
HIGH 8.8

Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.

CVE-2026-69517
HIGH 7.0

Use after free in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.

CVE-2026-69516
HIGH 7.0

Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM