Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

25,946 CVEs affect a tracked app or OS (all severities, all platforms). 373 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
25,946
Actively exploited
373
Publication window
1997-01-01 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

25,946 entries
CVE
CVE-2026-69455
HIGH 7.8

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-69453
MEDIUM 5.5

Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally.

CVE-2026-69451
HIGH 7.1

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges over a network.

CVE-2026-69450
HIGH 7.8

Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69449
MEDIUM 6.7

Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally.

CVE-2026-69448
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to eleva…

CVE-2026-69447
HIGH 7.8

Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69445
HIGH 7.8

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows Compressed Folder allows an authorized attacker to elevate privileges…

CVE-2026-69444
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

CVE-2026-69443
HIGH 7.5

Out-of-bounds read in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to disclose information over a …

CVE-2026-69441
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privi…

CVE-2026-69440
HIGH 7.0

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVE-2026-69438
HIGH 8.1

Incorrect conversion between numeric types in Microsoft JScript allows an unauthorized attacker to execute code over a network.

CVE-2026-69436
HIGH 7.8

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69434
HIGH 8.8

Heap-based buffer overflow in Windows URL Moniker allows an unauthorized attacker to execute code over a network.

CVE-2026-69433
HIGH 7.8

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69432
HIGH 7.8

Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69431
CRITICAL 9.8

Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.

CVE-2026-69430
HIGH 7.0

Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69429
HIGH 7.5

Heap-based buffer overflow in Windows IKE Extension allows an authorized attacker to execute code over a network.

CVE-2026-69428
HIGH 7.5

Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.

CVE-2026-69427
HIGH 8.0

Out-of-bounds read in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69426
HIGH 7.8

Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to execute code locally.

CVE-2026-69425
MEDIUM 4.7

Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally.

CVE-2026-69424
HIGH 7.8

Heap-based buffer overflow in Windows Distributed File System (DFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-69423
HIGH 8.0

Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network.

CVE-2026-69422
HIGH 7.0

Use after free in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69421
HIGH 7.8

Integer underflow (wrap or wraparound) in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69420
HIGH 7.8

Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.

CVE-2026-69418
HIGH 8.0

Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges over a network.

CVE-2026-69416
MEDIUM 5.7

Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

CVE-2026-69415
MEDIUM 6.8

Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network.

CVE-2026-69413
HIGH 7.0

Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69412
HIGH 8.0

Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.

CVE-2026-69410
HIGH 7.0

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-69408
CRITICAL 9.8

Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-69407
HIGH 7.8

Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69406
MEDIUM 5.5

Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-69405
MEDIUM 5.7

Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

CVE-2026-69404
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileg…

CVE-2026-69403
MEDIUM 5.5

Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally.

CVE-2026-69401
HIGH 7.0

Use after free in Audio Video Control Transport Protocol allows an authorized attacker to elevate privileges locally.

CVE-2026-69398
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to eleva…

CVE-2026-69397
HIGH 7.5

Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network.

CVE-2026-69396
HIGH 7.1

Use after free in Windows NDIS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69395
MEDIUM 6.5

Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a networ…

CVE-2026-69394
HIGH 7.0

Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69393
MEDIUM 5.7

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network.

CVE-2026-69392
HIGH 7.8

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

CVE-2026-69391
HIGH 7.8

Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM