Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,602 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,602
Actively exploited
294
Publication window
2004-07-27 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,602 entries High Clear all
CVE
CVE-2026-50484
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50482
HIGH 7.3

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-50480
HIGH 7.8

Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.

CVE-2026-50479
HIGH 7.8

Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50478
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50477
HIGH 8.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50476
HIGH 7.8

Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.

CVE-2026-50474
HIGH 8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-50471
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50470
HIGH 7.5

Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.

CVE-2026-50469
HIGH 7.8

Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50466
HIGH 7.8

Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50465
HIGH 7.1

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

CVE-2026-50463
HIGH 7.5

Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.

CVE-2026-50462
HIGH 7.8

External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-50461
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50460
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi…

CVE-2026-50459
HIGH 7.0

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

CVE-2026-50458
HIGH 7.8

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50457
HIGH 7.8

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50454
HIGH 7.8

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

CVE-2026-50452
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi…

CVE-2026-50451
HIGH 7.1

Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-50450
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized …

CVE-2026-50449
HIGH 7.0

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50448
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50444
HIGH 8.8

Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.

CVE-2026-50441
HIGH 7.8

Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-50440
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate p…

CVE-2026-50439
HIGH 8.1

Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.

CVE-2026-50436
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50435
HIGH 7.8

Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.

CVE-2026-50433
HIGH 7.8

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50429
HIGH 8.2

Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.

CVE-2026-50428
HIGH 7.1

Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

CVE-2026-50427
HIGH 7.8

Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-50425
HIGH 7.8

Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.

CVE-2026-50424
HIGH 7.5

Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.

CVE-2026-50423
HIGH 7.8

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50422
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50421
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate priv…

CVE-2026-50417
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-50414
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50413
HIGH 8.8

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50412
HIGH 7.8

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50411
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVE-2026-50410
HIGH 7.0

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50407
HIGH 7.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

CVE-2026-50406
HIGH 7.0

Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

CVE-2026-50405
HIGH 7.8

Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM