Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,495 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,495
Actively exploited
214
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,495 entries Windows Clear all
CVE
CVE-2026-62727
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva…

CVE-2026-75874
CRITICAL 10.0 1 app

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

CVE-2026-74990
CRITICAL 9.8 1 app

Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or …

CVE-2026-74989
CRITICAL 9.8 1 app

Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume th…

CVE-2026-74988
CRITICAL 9.8 1 app

Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevan…

CVE-2026-74987
CRITICAL 9.8 1 app

Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or …

CVE-2026-74983
HIGH 8.1 1 app

Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, T…

CVE-2026-74979
CRITICAL 9.8 1 app

Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

CVE-2026-74976
MEDIUM 6.5 1 app

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154…

CVE-2026-74974
MEDIUM 5.4 1 app

Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR…

CVE-2026-74973
MEDIUM 4.2 1 app

Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.…

CVE-2026-74972
MEDIUM 4.3 1 app

Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbir…

CVE-2026-74971
MEDIUM 4.3 1 app

Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Th…

CVE-2026-74969
HIGH 8.8 1 app

Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1,…

CVE-2026-74968
MEDIUM 5.4 1 app

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153…

CVE-2026-74967
MEDIUM 5.4 1 app

Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbi…

CVE-2026-74965
HIGH 8.8 1 app

Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, T…

CVE-2026-74964
CRITICAL 9.8 1 app

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 14…

CVE-2026-74963
MEDIUM 5.4 1 app

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird…

CVE-2026-74962
HIGH 8.1 1 app

Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154,…

CVE-2026-74961
CRITICAL 9.1 1 app

Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

CVE-2026-74958
HIGH 7.5 1 app

Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

CVE-2026-74956
CRITICAL 9.1 1 app

Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbi…

CVE-2026-74955
HIGH 8.8 1 app

Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

CVE-2026-74954
HIGH 7.5 1 app

Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154…

CVE-2026-74953
HIGH 8.8 1 app

Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154,…

CVE-2026-74952
HIGH 8.8 1 app

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

CVE-2026-74950
HIGH 8.8 1 app

Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

CVE-2026-74949
HIGH 8.8 1 app

Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 15…

CVE-2026-74947
HIGH 8.8 1 app

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thu…

CVE-2026-74946
HIGH 8.8 1 app

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.…

CVE-2026-74944
CRITICAL 9.8 1 app

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderb…

CVE-2026-74943
CRITICAL 9.8 1 app

Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thu…

CVE-2026-74942
HIGH 8.8 1 app

Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR …

CVE-2026-74941
HIGH 8.8 1 app

Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 15…

CVE-2026-74940
CRITICAL 9.8 1 app

Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunder…

CVE-2026-74939
HIGH 8.8 1 app

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, …

CVE-2026-74938
CRITICAL 9.1 1 app

Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

CVE-2026-74937
HIGH 8.8 1 app

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

CVE-2026-74936
CRITICAL 9.8 1 app

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, T…

CVE-2026-74935
HIGH 8.8 1 app

Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, …

CVE-2026-72971
MEDIUM 5.5

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to p…

CVE-2026-71331
HIGH 8.1

Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.

CVE-2026-70348
MEDIUM 5.5

Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.

CVE-2026-70347
HIGH 7.8

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70346
HIGH 7.8

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70345
HIGH 7.8

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70344
HIGH 7.8

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70330
MEDIUM 6.7

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-70307
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.