Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,013 CVEs affect a tracked app or OS (all severities, macOS). 103 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,013
Actively exploited
103
Publication window
2004-07-27 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,013 entries macOS Hide N/A Clear all
CVE
CVE-2024-2176
HIGH 8.8

Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2024-2174
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

CVE-2024-2173
HIGH 8.8

Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

CVE-2024-23296
HIGH 7.8 KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey…

CVE-2024-23225
HIGH 7.8 KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey…

CVE-2024-1939
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

CVE-2024-1938
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chrom…

CVE-2023-42853
MEDIUM 5.5

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to …

CVE-2024-1676
MEDIUM 5.4

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chr…

CVE-2024-1675
HIGH 8.8

Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted H…

CVE-2024-1674
HIGH 8.8

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HT…

CVE-2024-1673
HIGH 8.8

Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially explo…

CVE-2024-1672
MEDIUM 5.4

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via…

CVE-2024-1671
MEDIUM 6.5

Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafte…

CVE-2024-1670
HIGH 8.8

Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrom…

CVE-2024-1669
HIGH 8.8

Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTM…

CVE-2024-24699
MEDIUM 6.5

Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

CVE-2024-24698
MEDIUM 4.9

Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

CVE-2024-24690
MEDIUM 5.4

Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2024-21413
CRITICAL 9.8 KEV

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2024-21384
HIGH 7.8

Microsoft Office OneNote Remote Code Execution Vulnerability

CVE-2024-21379
HIGH 7.8

Microsoft Word Remote Code Execution Vulnerability

CVE-2024-21378
HIGH 8.8

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2024-20673
HIGH 7.8

Microsoft Office Remote Code Execution Vulnerability

CVE-2024-1284
CRITICAL 9.8

Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro…

CVE-2024-1283
CRITICAL 9.8

Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.…

CVE-2023-5841
CRITICAL 9.1

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing…

CVE-2024-1077
HIGH 8.8

Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chro…

CVE-2024-1060
HIGH 8.8

Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch…

CVE-2024-1059
HIGH 8.8

Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML…

CVE-2024-23743
LOW 3.3

Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must lau…

CVE-2023-52356
HIGH 7.5

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a re…

CVE-2024-0814
MEDIUM 6.5

Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (…

CVE-2024-0813
HIGH 8.8

Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially…

CVE-2024-0812
HIGH 8.8

Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a …

CVE-2024-0811
MEDIUM 4.3

Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extensio…

CVE-2024-0810
MEDIUM 4.3

Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension t…

CVE-2024-0809
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML p…

CVE-2024-0808
CRITICAL 9.8

Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chro…

CVE-2024-0807
HIGH 8.8

Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (…

CVE-2024-0806
HIGH 8.8

Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interactio…

CVE-2024-0805
MEDIUM 4.3

Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain nam…

CVE-2024-0804
HIGH 7.5

Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HT…

CVE-2024-23224
MEDIUM 5.5

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data.

CVE-2024-23223
MEDIUM 6.2

A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An …

CVE-2024-23222
HIGH 8.8 KEV

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS …

CVE-2024-23218
MEDIUM 5.9

A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPad…

CVE-2024-23217
LOW 3.3

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6…

CVE-2024-23215
MEDIUM 5.5

An issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. …

CVE-2024-23214
HIGH 8.8

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, …

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM