Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,602 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,602
Actively exploited
294
Publication window
2004-07-27 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,602 entries High Clear all
CVE
CVE-2026-55036
HIGH 7.8

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55033
HIGH 7.8

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55032
HIGH 7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-55031
HIGH 7.8

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55029
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55025
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-55024
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-54128
HIGH 8.4

Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.

CVE-2026-54125
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-54124
HIGH 7.8

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

CVE-2026-54121
HIGH 8.8

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

CVE-2026-54115
HIGH 7.8

Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

CVE-2026-50692
HIGH 8.8

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-50689
HIGH 7.8

Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

CVE-2026-50688
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50687
HIGH 8.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50686
HIGH 8.1

Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.

CVE-2026-50685
HIGH 7.5

Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.

CVE-2026-50683
HIGH 8.0

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.

CVE-2026-50682
HIGH 7.1

Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.

CVE-2026-50680
HIGH 8.2

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

CVE-2026-50679
HIGH 7.8

Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-50677
HIGH 7.8

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50676
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50674
HIGH 7.0

Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50673
HIGH 7.8

Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50672
HIGH 7.0

Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50670
HIGH 8.8

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50669
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-50667
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges…

CVE-2026-50666
HIGH 8.8

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.

CVE-2026-50655
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-50647
HIGH 7.5

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a n…

CVE-2026-50509
HIGH 7.8

Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50505
HIGH 7.5

Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.

CVE-2026-50503
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50502
HIGH 8.0

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

CVE-2026-50501
HIGH 7.8

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

CVE-2026-50500
HIGH 7.5

Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.

CVE-2026-50499
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-50498
HIGH 7.8

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

CVE-2026-50496
HIGH 7.5

Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50494
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-50493
HIGH 7.8

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50491
HIGH 7.0

Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-50490
HIGH 7.0

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-50489
HIGH 8.8

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-50488
HIGH 7.8

Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate …

CVE-2026-50487
HIGH 8.1

Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50486
HIGH 7.8

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM