Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,530 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,530
Actively exploited
214
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,530 entries Windows Clear all
CVE
CVE-2021-36960
HIGH 7.5

Windows SMB Information Disclosure Vulnerability

CVE-2021-36959
MEDIUM 5.5

Windows Authenticode Spoofing Vulnerability

CVE-2021-36955
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2021-36954
HIGH 8.8

Windows Bind Filter Driver Elevation of Privilege Vulnerability

CVE-2021-26435
HIGH 8.1

Windows Scripting Engine Memory Corruption Vulnerability

CVE-2021-40529
MEDIUM 5.9 1 app

The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between tw…

CVE-2021-40330
HIGH 7.5 1 app

git_connect_git in connect.c in Git before 2.30.1 allows a repository path to contain a newline character, which may result in unexpected cross-protocol reques…

CVE-2021-29989
HIGH 8.8 1 app

Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corruption and we pres…

CVE-2021-29988
HIGH 8.8 1 app

Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentially exploita…

CVE-2021-29987
MEDIUM 6.5 1 app

After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still…

CVE-2021-29986
HIGH 8.1 1 app

A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operati…

CVE-2021-29985
HIGH 8.8 1 app

A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbir…

CVE-2021-29984
HIGH 8.8 1 app

Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to me…

CVE-2021-29982
MEDIUM 6.5 1 app

Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential leak of a single bit of memory. Th…

CVE-2021-29981
HIGH 8.8 1 app

An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code that would lead to a po…

CVE-2021-29980
HIGH 8.8 1 app

Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerabil…

CVE-2021-36958
HIGH 7.8

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull…

CVE-2021-36948
HIGH 7.8 KEV

Windows Update Medic Service Elevation of Privilege Vulnerability

CVE-2021-36947
HIGH 8.8

Windows Print Spooler Remote Code Execution Vulnerability

CVE-2021-36942
HIGH 7.5 KEV

Windows LSA Spoofing Vulnerability

CVE-2021-36938
MEDIUM 5.5

Windows Cryptographic Primitives Library Information Disclosure Vulnerability

CVE-2021-36937
HIGH 7.8

Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability

CVE-2021-36936
HIGH 8.8

Windows Print Spooler Remote Code Execution Vulnerability

CVE-2021-36933
HIGH 7.5

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

CVE-2021-36932
HIGH 7.5

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

CVE-2021-36926
HIGH 7.5

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

CVE-2021-34537
HIGH 7.8

Windows Bluetooth Driver Elevation of Privilege Vulnerability

CVE-2021-34536
HIGH 7.8

Windows Storage Spaces Controller Elevation of Privilege Vulnerability

CVE-2021-34535
HIGH 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2021-34534
MEDIUM 6.8

Windows MSHTML Platform Remote Code Execution Vulnerability

CVE-2021-34533
HIGH 7.8

Windows Graphics Component Font Parsing Remote Code Execution Vulnerability

CVE-2021-34530
HIGH 7.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2021-34487
HIGH 7.0

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2021-34486
HIGH 7.8 KEV

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2021-34484
HIGH 7.8 KEV

Windows User Profile Service Elevation of Privilege Vulnerability

CVE-2021-34483
HIGH 7.8

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2021-34480
MEDIUM 6.8

Scripting Engine Memory Corruption Vulnerability

CVE-2021-26433
HIGH 7.5

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

CVE-2021-26432
CRITICAL 9.8

Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

CVE-2021-26431
HIGH 7.8

Windows Recovery Environment Agent Elevation of Privilege Vulnerability

CVE-2021-26426
HIGH 7.0

Windows User Account Profile Picture Elevation of Privilege Vulnerability

CVE-2021-26425
HIGH 7.8

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2021-26424
CRITICAL 9.9

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2021-29976
HIGH 8.8 1 app

Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory corruption …

CVE-2021-29970
HIGH 8.8 1 app

A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when acces…

CVE-2021-29969
MEDIUM 5.9 1 app

If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS ha…

CVE-2020-18173
HIGH 7.8 1 app

A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.

CVE-2021-36934
HIGH 7.8 KEV

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accoun…

CVE-2021-34481
HIGH 8.8

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull…

CVE-2021-34466
MEDIUM 5.7

Windows Hello Security Feature Bypass Vulnerability