Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,012 CVEs affect a tracked app or OS (all severities, macOS). 103 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,012
Actively exploited
103
Publication window
2004-07-27 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,012 entries macOS Hide N/A Clear all
CVE
CVE-2022-4914
HIGH 8.8

Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to poten…

CVE-2022-4913
MEDIUM 6.5

Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to spoof …

CVE-2022-4912
HIGH 8.8

Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2022-4911
MEDIUM 6.5

Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML…

CVE-2022-4910
MEDIUM 5.4

Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML…

CVE-2022-4909
MEDIUM 6.3

Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially perform an ASLR bypass via a crafted HTML …

CVE-2022-4908
MEDIUM 4.3

Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak cross-origin data via a crafted HTML p…

CVE-2022-4907
HIGH 8.8

Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pag…

CVE-2022-4906
HIGH 8.8

Inappropriate implementation in Blink in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page…

CVE-2021-4324
MEDIUM 6.5

Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to read arbitrary files via a malicious file.…

CVE-2021-4323
MEDIUM 6.5

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious…

CVE-2021-4322
HIGH 8.8

Use after free in DevTools in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to execute arbitrar…

CVE-2021-4321
MEDIUM 4.3

Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium se…

CVE-2021-4320
HIGH 8.8

Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/wr…

CVE-2021-4319
HIGH 8.8

Use after free in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium sec…

CVE-2021-4318
HIGH 8.8

Object corruption in Blink in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (…

CVE-2021-4317
HIGH 8.8

Use after free in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium sec…

CVE-2021-4316
MEDIUM 4.3

Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium…

CVE-2023-3598
HIGH 8.8

Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

CVE-2023-35311
HIGH 8.8 KEV

Microsoft Outlook Security Feature Bypass Vulnerability

CVE-2023-33150
CRITICAL 9.6

Microsoft Office Security Feature Bypass Vulnerability

CVE-2023-31486
HIGH · vendor

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2023-3497
MEDIUM 4.6

Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of ser…

CVE-2023-36539
MEDIUM 5.3

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVE-2023-3422
HIGH 8.8

Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially …

CVE-2023-3421
HIGH 8.8

Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2023-3420
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2023-32395
MEDIUM 5.5

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may …

CVE-2023-33133
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2023-33131
HIGH 8.8

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2023-32029
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2023-34114
HIGH 7.4

Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable infor…

CVE-2023-3217
HIGH 8.8

Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2023-3216
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2023-3215
HIGH 8.8

Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch…

CVE-2023-3214
HIGH 8.8

Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

CVE-2023-28600
MEDIUM 5.2

Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files poten…

CVE-2023-28599
MEDIUM 4.3

Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi…

CVE-2023-3079
HIGH 8.8 KEV

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2022-35742
HIGH 7.5

Microsoft Outlook Denial of Service Vulnerability

CVE-2023-2941
MEDIUM 4.3

Inappropriate implementation in Extensions API in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extensio…

CVE-2023-2940
MEDIUM 6.5

Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to …

CVE-2023-2939
HIGH 7.8

Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation via craft…

CVE-2023-2938
MEDIUM 4.3

Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process t…

CVE-2023-2937
MEDIUM 4.3

Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process t…

CVE-2023-2936
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

CVE-2023-2935
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

CVE-2023-2934
HIGH 8.8

Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

CVE-2023-2933
HIGH 8.8

Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromiu…

CVE-2023-2932
HIGH 8.8

Use after free in PDF in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromiu…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM