Vulnerabilities
Tracked app vulnerabilities
3,429 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 3,429
- Actively exploited
- 21
- Publication window
- 2009-07-30 → 2026-09-17
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-80160
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabil… |
|
CVE-2026-80159
Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage… |
|
CVE-2026-79910
Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerabil… |
|
CVE-2026-85875
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-83951
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-83949
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-83501
MEDIUM 5.5
Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. |
|
CVE-2026-81958
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-81401
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-81400
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-81399
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-81395
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-81394
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information lo… |
|
CVE-2026-81393
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-81392
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-81391
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-81390
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-81387
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information lo… |
|
CVE-2026-80090
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-80079
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-80073
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-78523
MEDIUM 5.9
Use after free in Windows DNS allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-78522
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-78520
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-78516
MEDIUM 4.3
Insertion of sensitive information into externally-accessible file or directory in Windows Storage allows an authorized attacker to disclose information locall… |
|
CVE-2026-78513
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-78508
MEDIUM 4.6
Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-78506
Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-78503
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-78502
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-78455
MEDIUM 4.3
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-78454
MEDIUM 5.5
Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-78453
MEDIUM 6.5
Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-78452
MEDIUM 4.6
Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-78451
MEDIUM 6.8
Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-78446
MEDIUM 5.3
Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network. |
|
CVE-2026-77911
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-77892
MEDIUM 6.8
No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-77891
MEDIUM 6.4
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally. |
|
CVE-2026-77887
MEDIUM 6.4
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally. |
|
CVE-2026-77492
MEDIUM 5.5
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-77491
MEDIUM 5.5
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-73019
MEDIUM 4.3
Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-73008
MEDIUM 5.5
Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-73004
MEDIUM 5.5
Missing authentication for critical function in Windows Autopilot allows an authorized attacker to perform tampering locally. |
|
CVE-2026-72999
MEDIUM 6.8
Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-72985
MEDIUM 6.8
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-72980
MEDIUM 4.4
Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-72978
MEDIUM 5.9
Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a net… |
|
CVE-2026-72977
Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.