Vulnerabilities
Tracked app vulnerabilities
3,429 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 3,429
- Actively exploited
- 21
- Publication window
- 2009-07-30 → 2026-09-17
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-69672
MEDIUM 5.5
Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally. |
|
CVE-2026-69637
MEDIUM 5.7
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. |
|
CVE-2026-69627
MEDIUM 5.5
Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-69624
MEDIUM 6.5
Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network. |
|
CVE-2026-69618
MEDIUM 5.5
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information locally. |
|
CVE-2026-69616
MEDIUM 5.5
Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally. |
|
CVE-2026-69609
MEDIUM 5.5
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. |
|
CVE-2026-69591
MEDIUM 5.7
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69572
MEDIUM 5.7
Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69569
MEDIUM 5.7
Untrusted pointer dereference in Windows Print Spooler Components allows an authorized attacker to deny service over a network. |
|
CVE-2026-69568
MEDIUM 5.5
Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to disclose information locally. |
|
CVE-2026-69566
MEDIUM 6.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-69554
MEDIUM 5.5
Missing authentication for critical function in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally. |
|
CVE-2026-69552
MEDIUM 5.7
Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a n… |
|
CVE-2026-69548
MEDIUM 4.6
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-69531
MEDIUM 5.5
Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally. |
|
CVE-2026-69527
MEDIUM 5.5
Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-69507
MEDIUM 5.7
Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose… |
|
CVE-2026-69504
MEDIUM 5.5
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-69497
MEDIUM 6.5
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over a network. |
|
CVE-2026-69490
MEDIUM 6.8
Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-69483
MEDIUM 4.7
Out-of-bounds read in Windows Image Acquisition allows an authorized attacker to disclose information locally. |
|
CVE-2026-69474
MEDIUM 4.8
Use after free in Windows Overlay Filter allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69469
MEDIUM 6.6
Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-69457
MEDIUM 5.5
Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-69453
MEDIUM 5.5
Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally. |
|
CVE-2026-69449
MEDIUM 6.7
Heap-based buffer overflow in Windows BitLocker allows an authorized attacker to execute code locally. |
|
CVE-2026-69425
MEDIUM 4.7
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally. |
|
CVE-2026-69416
MEDIUM 5.7
Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. |
|
CVE-2026-69415
MEDIUM 6.8
Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-69406
MEDIUM 5.5
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-69405
MEDIUM 5.7
Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. |
|
CVE-2026-69403
MEDIUM 5.5
Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally. |
|
CVE-2026-69395
MEDIUM 6.5
Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a networ… |
|
CVE-2026-69393
MEDIUM 5.7
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69390
MEDIUM 5.5
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally. |
|
CVE-2026-69381
MEDIUM 4.6
Out-of-bounds read in Windows Storage Port Driver allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-69376
MEDIUM 5.5
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
|
CVE-2026-69374
MEDIUM 6.5
Allocation of resources without limits or throttling in Windows SMB Server allows an authorized attacker to deny service over a network. |
|
CVE-2026-69373
MEDIUM 6.7
Integer overflow or wraparound in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69372
MEDIUM 5.7
Out-of-bounds read in Windows Network File System allows an authorized attacker to deny service over a network. |
|
CVE-2026-69369
MEDIUM 5.5
Out-of-bounds read in Windows DNS allows an authorized attacker to disclose information locally. |
|
CVE-2026-69367
MEDIUM 5.5
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
|
CVE-2026-69353
MEDIUM 5.5
Out-of-bounds read in Windows Text Shaping allows an authorized attacker to disclose information locally. |
|
CVE-2026-69351
MEDIUM 5.5
Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclo… |
|
CVE-2026-69350
MEDIUM 6.7
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-69349
MEDIUM 5.7
Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69345
MEDIUM 5.5
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
|
CVE-2026-69344
MEDIUM 5.5
Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. |
|
CVE-2026-69343
MEDIUM 5.5
Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to disclose information locally. |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.