Vulnerabilities
Tracked app vulnerabilities
3,429 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 3,429
- Actively exploited
- 21
- Publication window
- 2009-07-30 → 2026-09-17
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-69339
MEDIUM 5.5
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information… |
|
CVE-2026-69321
MEDIUM 5.5
Missing authentication for critical function in Windows Power Dependency Coordinator allows an authorized attacker to perform tampering locally. |
|
CVE-2026-69318
MEDIUM 5.5
Out-of-bounds read in Windows Imaging Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-69317
MEDIUM 5.7
Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69316
MEDIUM 4.7
Buffer over-read in Windows Overlay Filter allows an authorized attacker to disclose information locally. |
|
CVE-2026-69315
MEDIUM 5.5
Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information loc… |
|
CVE-2026-69308
MEDIUM 5.5
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
|
CVE-2026-69297
MEDIUM 6.5
Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. |
|
CVE-2026-69294
MEDIUM 5.5
Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally. |
|
CVE-2026-69288
MEDIUM 5.5
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. |
|
CVE-2026-69286
MEDIUM 5.5
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to disclose information locally. |
|
CVE-2026-69267
MEDIUM 6.5
Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally. |
|
CVE-2026-68898
MEDIUM 6.5
Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-68895
MEDIUM 5.5
Numeric truncation error in Internet Storage Name Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-68891
MEDIUM 4.7
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
|
CVE-2026-68886
MEDIUM 5.5
Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally. |
|
CVE-2026-68881
MEDIUM 5.5
Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally. |
|
CVE-2026-68874
MEDIUM 5.7
Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network. |
|
CVE-2026-68873
MEDIUM 5.5
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information local… |
|
CVE-2026-68852
MEDIUM 5.5
Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally. |
|
CVE-2026-68851
MEDIUM 5.5
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. |
|
CVE-2026-68849
MEDIUM 4.7
Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally. |
|
CVE-2026-68843
MEDIUM 5.5
Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally. |
|
CVE-2026-68842
MEDIUM 5.5
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information… |
|
CVE-2026-68833
MEDIUM 6.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-68831
MEDIUM 5.5
Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-68830
MEDIUM 5.5
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose … |
|
CVE-2026-62801
MEDIUM 6.5
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security featu… |
|
CVE-2026-62762
MEDIUM 6.5
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. |
|
CVE-2026-85044
Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web … |
|
CVE-2026-84358
Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof … |
|
CVE-2026-84357
Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin polic… |
|
CVE-2026-84356
UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium se… |
|
CVE-2026-84348
Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML… |
|
CVE-2026-84332
Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HT… |
|
CVE-2026-84330
UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page… |
|
CVE-2026-84329
Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process … |
|
CVE-2026-84327
Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sen… |
|
CVE-2026-84323
Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged so… |
|
CVE-2026-84139
Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
CVE-2026-84138
Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |
|
CVE-2026-84137
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
CVE-2026-84136
Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
CVE-2026-84126
Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and Thunderbird 155. |
|
CVE-2026-84125
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
CVE-2026-84124
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderb… |
|
CVE-2026-84122
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 1… |
|
CVE-2026-84120
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbir… |
|
CVE-2026-84118
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. |
|
CVE-2026-25250
MEDIUM 6.0
EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable." |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.