Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

25,946 CVEs affect a tracked app or OS (all severities, all platforms). 373 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
25,946
Actively exploited
373
Publication window
1997-01-01 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

25,946 entries
CVE
CVE-2026-69514
HIGH 7.5

Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-69513
HIGH 7.8

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69512
HIGH 8.0

Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.

CVE-2026-69511
HIGH 8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-69510
HIGH 8.1

Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

CVE-2026-69509
HIGH 7.8

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69508
HIGH 7.8

Stack-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVE-2026-69507
MEDIUM 5.7

Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose…

CVE-2026-69505
HIGH 8.0

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69504
MEDIUM 5.5

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

CVE-2026-69503
HIGH 8.0

Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network.

CVE-2026-69501
HIGH 7.0

Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-69500
HIGH 7.0

Use after free in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.

CVE-2026-69499
HIGH 8.8

Integer overflow or wraparound in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-69498
HIGH 7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69497
MEDIUM 6.5

Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network.

CVE-2026-69496
CRITICAL 9.8

Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.

CVE-2026-69495
HIGH 8.8

Heap-based buffer overflow in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

CVE-2026-69494
HIGH 8.8

Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

CVE-2026-69493
CRITICAL 9.8

Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

CVE-2026-69492
HIGH 7.0

Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69491
CRITICAL 9.8

Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.

CVE-2026-69490
MEDIUM 6.8

Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-69489
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69488
HIGH 7.0

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69485
HIGH 8.8

Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.

CVE-2026-69483
MEDIUM 4.7

Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally.

CVE-2026-69482
HIGH 7.1

Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.

CVE-2026-69481
HIGH 8.0

Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.

CVE-2026-69480
HIGH 7.8

Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69479
HIGH 8.4

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-69478
HIGH 7.8

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69476
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69475
HIGH 7.8

Untrusted pointer dereference in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-69474
MEDIUM 4.8

Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network.

CVE-2026-69473
HIGH 7.0

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-69472
HIGH 7.0

Use after free in Windows Devices Human Interface allows an authorized attacker to elevate privileges locally.

CVE-2026-69470
HIGH 7.0

Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

CVE-2026-69469
MEDIUM 6.6

Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-69468
HIGH 7.0

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69467
HIGH 7.8

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69466
HIGH 7.0

Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-69463
CRITICAL 9.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.

CVE-2026-69462
HIGH 8.0

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.

CVE-2026-69461
HIGH 8.8

Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.

CVE-2026-69460
HIGH 7.1

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network.

CVE-2026-69459
HIGH 7.8

Heap-based buffer overflow in Windows Power Dependency Coordinator allows an authorized attacker to elevate privileges locally.

CVE-2026-69458
HIGH 8.0

Out-of-bounds read in Windows BitLocker allows an authorized attacker to elevate privileges over a network.

CVE-2026-69457
MEDIUM 5.5

Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally.

CVE-2026-69456
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM