Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,601 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,601
Actively exploited
294
Publication window
2004-07-27 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,601 entries High Clear all
CVE
CVE-2026-50404
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50403
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50402
HIGH 7.8

Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-50400
HIGH 7.8

Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-50399
HIGH 7.8

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50398
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50397
HIGH 7.0

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50396
HIGH 7.0

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-50393
HIGH 7.0

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-50392
HIGH 7.0

Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-50391
HIGH 7.8

Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.

CVE-2026-50390
HIGH 7.0

Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50388
HIGH 7.8

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50387
HIGH 7.8

Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.

CVE-2026-50386
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-50385
HIGH 8.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50382
HIGH 8.8

Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.

CVE-2026-50379
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privilege…

CVE-2026-50378
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privi…

CVE-2026-50373
HIGH 7.8

Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-50372
HIGH 7.0

Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.

CVE-2026-50371
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privilege…

CVE-2026-50370
HIGH 8.8

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-50369
HIGH 8.8

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

CVE-2026-50368
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

CVE-2026-50367
HIGH 7.8

Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50365
HIGH 8.0

Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.

CVE-2026-50363
HIGH 7.8

Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-50362
HIGH 7.8

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.

CVE-2026-50361
HIGH 7.8

Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50360
HIGH 8.8

Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

CVE-2026-50359
HIGH 7.0

Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.

CVE-2026-50358
HIGH 7.0

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50357
HIGH 7.8

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

CVE-2026-50355
HIGH 7.5

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

CVE-2026-50353
HIGH 7.8

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVE-2026-50348
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privi…

CVE-2026-50347
HIGH 7.8

Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.

CVE-2026-50346
HIGH 7.8

Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50345
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privile…

CVE-2026-50344
HIGH 7.8

Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.

CVE-2026-50343
HIGH 7.8

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50340
HIGH 8.5

Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.

CVE-2026-50337
HIGH 7.8

Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.

CVE-2026-50336
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-50335
HIGH 7.8

Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.

CVE-2026-50332
HIGH 7.8

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50331
HIGH 7.8

Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.

CVE-2026-50330
HIGH 7.5

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50329
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM