Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,601 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,601
Actively exploited
294
Publication window
2004-07-27 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,601 entries High Clear all
CVE
CVE-2026-80080
HIGH 8.8

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-80075
HIGH 7.8

Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.

CVE-2026-78525
HIGH 8.8

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

CVE-2026-78521
HIGH 8.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78519
HIGH 8.8

Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

CVE-2026-78518
HIGH 8.8

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

CVE-2026-78517
HIGH 8.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78514
HIGH 8.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78512
HIGH 8.8

Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78511
HIGH 8.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78504
HIGH 8.8

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-78464
HIGH 7.0

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

CVE-2026-78457
HIGH 7.0

Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.

CVE-2026-78450
HIGH 8.1

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

CVE-2026-78449
HIGH 8.1

Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.

CVE-2026-78448
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-78444
HIGH 8.1

Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.

CVE-2026-77905
HIGH 7.0

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

CVE-2026-77904
HIGH 7.8

Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-77901
HIGH 8.8

Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-77899
HIGH 7.0

Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.

CVE-2026-77895
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77894
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privi…

CVE-2026-77893
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77890
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77889
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77888
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77886
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77505
HIGH 8.1

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

CVE-2026-77504
HIGH 8.8

Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-77503
HIGH 8.4

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

CVE-2026-77502
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77501
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77500
HIGH 7.8

Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

CVE-2026-77499
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77498
HIGH 7.5

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77495
HIGH 8.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-77494
HIGH 7.5

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-77489
HIGH 7.8

Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73026
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73024
HIGH 7.8

Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-73023
HIGH 8.8

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-73022
HIGH 7.0

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVE-2026-73021
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73020
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73018
HIGH 8.8

Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.

CVE-2026-73017
HIGH 7.5

Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attacker to execute code locally.

CVE-2026-73016
HIGH 8.8

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2026-73015
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73014
HIGH 7.8

Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM