Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

25,946 CVEs affect a tracked app or OS (all severities, all platforms). 373 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
25,946
Actively exploited
373
Publication window
1997-01-01 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

25,946 entries
CVE
CVE-2026-69328
HIGH 7.8

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-69325
HIGH 8.1

Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.

CVE-2026-69324
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.

CVE-2026-69323
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69322
HIGH 8.0

Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

CVE-2026-69321
MEDIUM 5.5

Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally.

CVE-2026-69319
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevat…

CVE-2026-69318
MEDIUM 5.5

Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally.

CVE-2026-69317
MEDIUM 5.7

Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network.

CVE-2026-69316
MEDIUM 4.7

Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally.

CVE-2026-69315
MEDIUM 5.5

Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information loc…

CVE-2026-69314
HIGH 7.1

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69313
HIGH 7.1

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69312
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-69311
HIGH 7.0

Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69310
HIGH 7.0

Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-69309
HIGH 7.0

Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-69308
MEDIUM 5.5

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

CVE-2026-69307
HIGH 7.8

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69305
HIGH 7.1

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.

CVE-2026-69303
MEDIUM 5.5

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

CVE-2026-69301
HIGH 8.0

Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.

CVE-2026-69300
HIGH 7.0

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-69299
HIGH 7.0

Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally.

CVE-2026-69298
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69297
MEDIUM 6.5

Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network.

CVE-2026-69296
HIGH 7.1

Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-69295
HIGH 7.8

Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69294
MEDIUM 5.5

Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

CVE-2026-69293
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69292
HIGH 7.0

Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69291
HIGH 8.8

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-69290
HIGH 7.8

Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

CVE-2026-69289
HIGH 7.8

Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.

CVE-2026-69288
MEDIUM 5.5

Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

CVE-2026-69287
HIGH 7.0

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

CVE-2026-69286
MEDIUM 5.5

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally.

CVE-2026-69284
HIGH 7.8

Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.

CVE-2026-69283
HIGH 7.8

Heap-based buffer overflow in Windows CD-ROM Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69281
HIGH 7.0

Use after free in Windows License Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-69280
HIGH 7.0

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-69279
HIGH 7.0

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69277
HIGH 7.8

Stack-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.

CVE-2026-69276
CRITICAL 9.8

Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.

CVE-2026-69275
HIGH 7.0

Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69274
HIGH 7.1

Use after free in Windows Win32K allows an authorized attacker to elevate privileges over a network.

CVE-2026-69272
HIGH 7.1

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69271
HIGH 8.0

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

CVE-2026-69270
HIGH 7.8

Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

CVE-2026-69269
HIGH 7.8

Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM