Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,602 CVEs affect a tracked app or OS (High, all platforms). 294 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,602
Actively exploited
294
Publication window
2004-07-27 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,602 entries High Clear all
CVE
CVE-2026-72926
HIGH 7.0

Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.

CVE-2026-71353
HIGH 7.0

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-71352
HIGH 8.8

Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.

CVE-2026-71351
HIGH 7.0

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-71345
HIGH 7.8

Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.

CVE-2026-71343
HIGH 7.8

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.

CVE-2026-71342
HIGH 7.0

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-71340
HIGH 7.0

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

CVE-2026-71337
HIGH 7.8

Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

CVE-2026-71336
HIGH 8.8

Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.

CVE-2026-71334
HIGH 7.8

Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.

CVE-2026-71333
HIGH 7.0

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-71332
HIGH 7.0

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.

CVE-2026-71330
HIGH 7.5

Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to dis…

CVE-2026-70587
HIGH 7.5

Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

CVE-2026-70586
HIGH 8.8

Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.

CVE-2026-70585
HIGH 7.0

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.

CVE-2026-70584
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

CVE-2026-70581
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70579
HIGH 7.5

Out-of-bounds read in Windows Mobile Broadband allows an unauthorized attacker to disclose information over a network.

CVE-2026-70578
HIGH 7.0

Heap-based buffer overflow in Windows Credential Guard allows an authorized attacker to elevate privileges locally.

CVE-2026-70577
HIGH 7.0

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVE-2026-70574
HIGH 7.8

Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-70573
HIGH 7.0

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70572
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70570
HIGH 7.5

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-70569
HIGH 7.8

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-70568
HIGH 7.0

Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70567
HIGH 7.0

Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70565
HIGH 7.0

Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.

CVE-2026-70564
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-70563
HIGH 8.1

Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-70562
HIGH 7.0

Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70342
HIGH 8.1

Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-70289
HIGH 7.8

Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

CVE-2026-70283
HIGH 7.0

Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-70203
HIGH 8.8

Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

CVE-2026-70065
HIGH 7.5

Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-69989
HIGH 8.1

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

CVE-2026-69921
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-69911
HIGH 7.0

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69907
HIGH 7.8

Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.

CVE-2026-69906
HIGH 8.2

Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-69900
HIGH 7.8

Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69896
HIGH 7.0

Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69891
HIGH 7.0

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

CVE-2026-69890
HIGH 7.5

Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.

CVE-2026-69889
HIGH 7.0

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2026-69881
HIGH 7.5

Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network.

CVE-2026-69876
HIGH 8.0

Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM