Vulnerabilities
Tracked app vulnerabilities
15,602 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 15,602
- Actively exploited
- 294
- Publication window
- 2004-07-27 → 2026-09-17
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-58530
HIGH 7.8
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. |
|
CVE-2026-58529
HIGH 7.1
Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. |
|
CVE-2026-58527
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile… |
|
CVE-2026-57096
HIGH 7.8
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57094
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-57093
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57091
HIGH 7.8
Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57090
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-57089
HIGH 7.5
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-57088
HIGH 7.8
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-57087
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-56650
HIGH 7.8
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56648
HIGH 7.5
Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-56647
HIGH 8.8
Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-56644
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56643
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56194
HIGH 8.8
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-56189
HIGH 7.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. |
|
CVE-2026-56187
HIGH 7.0
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56186
HIGH 8.1
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. |
|
CVE-2026-56183
HIGH 7.0
Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56182
HIGH 7.8
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56181
HIGH 8.3
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. |
|
CVE-2026-56176
HIGH 7.8
Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56175
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56173
HIGH 7.0
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-55949
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55947
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55141
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55137
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55136
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55134
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55132
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55131
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55130
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55128
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55127
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55123
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55122
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-55120
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55058
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55055
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55053
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55048
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55044
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55043
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55041
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55039
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55038
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-55037
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.