Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

16,453 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
16,453
Actively exploited
286
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

16,453 entries
CVE
CVE-2025-47975
HIGH 7.0

Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability

CVE-2025-47973
HIGH 7.8

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-47972
HIGH 8.0

Windows Input Method Editor (IME) Elevation of Privilege Vulnerability

CVE-2025-47971
HIGH 7.8

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-47159
HIGH 7.8

Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability

CVE-2025-33054
HIGH 8.1

Remote Desktop Spoofing Vulnerability

CVE-2025-26636
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2024-36357
CRITICAL 5.6

AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue

CVE-2024-36350
CRITICAL 5.6

AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue

CVE-2025-32462
LOW 2.8

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on …

CVE-2025-6436
HIGH 8.1 1 app

Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-6435
HIGH 8.1 1 app

If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file …

CVE-2025-6218
HIGH 7.8 KEV 1 app

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install…

CVE-2025-43200
MEDIUM 4.2 KEV

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.…

CVE-2025-5986
MEDIUM 6.5 1 app

A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompti…

CVE-2025-2884
MEDIUM 6.6

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with…

CVE-2025-47953
CRITICAL 8.4 1 app

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47167
CRITICAL 8.4 1 app

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47164
CRITICAL 8.4 1 app

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47162
CRITICAL 8.4 1 app

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47969
HIGH 4.4

Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability

CVE-2025-47955
HIGH 7.8

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-47160
HIGH 5.4

Windows Shortcut Files Security Feature Bypass Vulnerability

CVE-2025-33075
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2025-33073
HIGH 8.8 KEV

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2025-33071
CRITICAL 8.1

Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability

CVE-2025-33070
CRITICAL 8.1

Windows Netlogon Elevation of Privilege Vulnerability

CVE-2025-33069
HIGH 5.1

Windows App Control for Business Security Feature Bypass Vulnerability

CVE-2025-33068
HIGH 7.5

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

CVE-2025-33067
HIGH 8.4

Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2025-33066
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-33065
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33064
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-33063
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33062
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33061
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33060
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33059
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33058
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33057
HIGH 6.5

Windows Local Security Authority (LSA) Denial of Service Vulnerability

CVE-2025-33056
HIGH 7.5

Windows Local Security Authority (LSA) Denial of Service Vulnerability

CVE-2025-33055
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability

CVE-2025-33053
HIGH 8.8 KEV

Internet Shortcut Files Remote Code Execution Vulnerability

CVE-2025-33052
HIGH 5.5

Windows DWM Core Library Information Disclosure Vulnerability

CVE-2025-33050
HIGH 7.5

DHCP Server Service Denial of Service Vulnerability

CVE-2025-32725
HIGH 7.5

DHCP Server Service Denial of Service Vulnerability

CVE-2025-32724
HIGH 7.5

Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability

CVE-2025-32722
HIGH 5.5

Windows Storage Port Driver Information Disclosure Vulnerability

CVE-2025-32721
HIGH 7.3

Windows Recovery Driver Elevation of Privilege Vulnerability

CVE-2025-32720
HIGH 5.5

Windows Storage Management Provider Information Disclosure Vulnerability