Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,652 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,652
Actively exploited
286
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,652 entries Hide N/A Clear all
CVE
CVE-2023-38152
HIGH 5.3

DHCP Server Service Information Disclosure Vulnerability

CVE-2023-38150
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-38149
HIGH 7.5

Windows TCP/IP Denial of Service Vulnerability

CVE-2023-38148
CRITICAL 8.8

Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

CVE-2023-38147
HIGH 8.8

Windows Miracast Wireless Display Remote Code Execution Vulnerability

CVE-2023-38146
HIGH 8.8

Windows Themes Remote Code Execution Vulnerability

CVE-2023-38144
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-38143
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-38142
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-38141
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-38140
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2023-38139
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-36805
HIGH 7.0

Windows MSHTML Platform Security Feature Bypass Vulnerability

CVE-2023-36804
HIGH 7.8

Windows GDI Elevation of Privilege Vulnerability

CVE-2023-36803
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2023-36802
HIGH 7.8 KEV

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CVE-2023-36801
HIGH 5.3

DHCP Server Service Information Disclosure Vulnerability

CVE-2023-35355
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-4585
HIGH 8.8 1 app

Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume tha…

CVE-2023-4584
HIGH 8.8 1 app

Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence…

CVE-2023-4583
HIGH 7.5 1 app

When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been dis…

CVE-2023-4582
HIGH 8.8 1 app

Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory…

CVE-2023-4581
MEDIUM 4.3 1 app

Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their pot…

CVE-2023-4580
MEDIUM 6.5 1 app

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability …

CVE-2023-4578
MEDIUM 6.5 1 app

When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function coul…

CVE-2023-4577
MEDIUM 6.5 1 app

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could pot…

CVE-2023-4576
HIGH 8.6 1 app

On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that…

CVE-2023-4575
MEDIUM 6.5 1 app

When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simul…

CVE-2023-4574
MEDIUM 6.5 1 app

When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simu…

CVE-2023-4573
MEDIUM 6.5 1 app

When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exp…

CVE-2022-32920
MEDIUM 5.5 1 app

The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may lead to disclosure of user information.

CVE-2023-35687
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35684
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35683
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35682
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35681
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35680
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35679
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35677
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35676
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35675
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35674
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35673
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35671
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35670
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35669
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35667
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35666
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35665
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-35664
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.