Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

8,497 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-62696
HIGH 7.8 Local

Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

CVE-2026-62695
HIGH 7.8 Local

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-62693
HIGH 7.0 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to ele…

CVE-2026-62692
HIGH 7.8 Local

Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-62690
HIGH 7.0 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-62688
HIGH 7.8 Local

Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVE-2026-61939
HIGH 7.0 Local

Use after free in Winlogon allows an authorized attacker to elevate privileges locally.

CVE-2026-61938
HIGH 7.0 Local

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-61937
HIGH 7.8 Local

Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-61934
HIGH 7.8 Local

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-61932
HIGH 7.8 Local

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-61930
HIGH 7.8 Local

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-61929
HIGH 7.0 Local

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-61927
HIGH 7.0 Local

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-61926
HIGH 7.8 Local

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-61925
HIGH 7.8 Local

Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-61920
MEDIUM 6.6 Network

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a…

CVE-2026-61367
HIGH 7.8 Local

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-61365
HIGH 7.8 Local

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-61364
HIGH 7.8 Local

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-61363
HIGH 7.5 Network

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-61361
HIGH 7.0 Local

Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.

CVE-2026-61359
HIGH 7.8 Local

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-61356
HIGH 7.8 Local

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-61355
HIGH 7.8 Local

Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVE-2026-61353
HIGH 7.8 Local

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

CVE-2026-61349
HIGH 7.8 Local

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

CVE-2026-61348
HIGH 7.0 Local

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-59134
HIGH 7.5 Network

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-59127
HIGH 7.8 Local

Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-59126
HIGH 7.0 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to e…

CVE-2026-59122
HIGH 7.0 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-56174
HIGH 7.8 Local

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVE-2026-50472
HIGH 7.0 Local

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

CVE-2026-49179
HIGH 8.8 Network

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code…

CVE-2026-42976
HIGH 7.8 Local

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.

CVE-2026-72971
HIGH 5.5

Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability

CVE-2026-70348
HIGH 5.5

Windows Management Services Denial of Service Vulnerability

CVE-2026-70347
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2026-70346
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2026-70345
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2026-70344
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2026-70330
HIGH 6.7

Windows DNS Elevation of Privilege Vulnerability

CVE-2026-70304
HIGH 6.7

Windows DNS Elevation of Privilege Vulnerability

CVE-2026-68819
HIGH 5.9

Windows Network File System Denial of Service Vulnerability

CVE-2026-6727
HIGH 5.9

MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability

CVE-2026-6726
HIGH 7.9

MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse

CVE-2026-66804
HIGH 7.8

Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability

CVE-2026-66799
CRITICAL 7.8

Windows Key Guard Elevation of Privilege Vulnerability

CVE-2026-65796
HIGH 5.9

Windows iSCSI Target Service Denial of Service Vulnerability