Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

53 CVEs affect a tracked app or OS (Critical, all platforms). 33 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
53
Actively exploited
33
Publication window
2010-06-30 → 2025-10-14

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

53 entries Critical Public exploit Clear all
CVE
CVE-2025-59287
CRITICAL 9.8 KEV

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2025-24085
CRITICAL 10.0 KEV

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS…

CVE-2024-6387
CRITICAL 8.1

RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling

CVE-2022-21907
CRITICAL 9.8

HTTP Protocol Stack Remote Code Execution Vulnerability

CVE-2021-44228
CRITICAL 10.0 KEV 1 app

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter…

CVE-2020-1472
CRITICAL 10.0 KEV

Netlogon Elevation of Privilege Vulnerability

CVE-2020-0796
CRITICAL 10.0 KEV

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S…

CVE-2014-4650
CRITICAL 9.8 1 app

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attacke…

CVE-2020-0610
CRITICAL 9.8

Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability

CVE-2020-0609
CRITICAL 9.8

Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability

CVE-2019-1152
CRITICAL 8.8

Microsoft Graphics Remote Code Execution Vulnerability

CVE-2019-1151
CRITICAL 8.8

Microsoft Graphics Remote Code Execution Vulnerability

CVE-2019-1150
CRITICAL 8.8

Microsoft Graphics Remote Code Execution Vulnerability

CVE-2019-1149
CRITICAL 8.8

Microsoft Graphics Remote Code Execution Vulnerability

CVE-2019-1145
CRITICAL 8.8

Microsoft Graphics Remote Code Execution Vulnerability

CVE-2019-1144
CRITICAL 8.8

Microsoft Graphics Remote Code Execution Vulnerability

CVE-2019-11708
CRITICAL 10.0 KEV 1 app

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op…

CVE-2019-11705
CRITICAL 9.8 1 app

A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in …

CVE-2019-11704
CRITICAL 9.8 1 app

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting…

CVE-2019-11703
CRITICAL 9.8 1 app

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a pot…

CVE-2019-2107
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2019-9792
CRITICAL 9.8 1 app

The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then b…

CVE-2019-9791
CRITICAL 9.8 1 app

The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just…

CVE-2018-8544
CRITICAL 7.5

Windows VBScript Engine Remote Code Execution Vulnerability

CVE-2018-5159
CRITICAL 9.8 1 app

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds wr…

CVE-2017-5465
CRITICAL 9.1 1 app

An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied i…

CVE-2017-5447
CRITICAL 9.1 1 app

An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to …

CVE-2017-5404
CRITICAL 9.8 1 app

A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results i…

CVE-2017-5375
CRITICAL 9.8 1 app

JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird <…

CVE-2016-9899
CRITICAL 9.8 1 app

Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 5…

CVE-2017-9417
CRITICAL 8.8

Broadcom BCM43xx Remote Code Execution Vulnerability

CVE-2017-8682
CRITICAL 8.4

Win32k Graphics Remote Code Execution Vulnerability

CVE-2017-11120
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2017-0781
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2017-8464
CRITICAL 7.5 KEV

LNK Remote Code Execution Vulnerability

CVE-2017-0283
CRITICAL 8.8

Windows Uniscribe Remote Code Execution Vulnerability

CVE-2016-10277
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2017-0561
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2017-0148
CRITICAL 8.1 KEV

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0146
CRITICAL 8.1 KEV

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0143
CRITICAL 8.1 KEV

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0084
CRITICAL 8.8

Windows Uniscribe Remote Code Execution Vulnerability

CVE-2016-7274
CRITICAL 7.5

Windows Uniscribe Remote Code Execution Vulnerability

CVE-2016-5195
CRITICAL KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2016-6828
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2016-2184
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2016-3861
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2016-3134
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2016-3301
CRITICAL 8.8

Microsoft Graphics Remote Code Execution Vulnerability

CVE-2014-1511
CRITICAL 9.8 1 app

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocke…