Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,012 CVEs affect a tracked app or OS (all severities, macOS). 103 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,012
Actively exploited
103
Publication window
2004-07-27 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,012 entries macOS Hide N/A Clear all
CVE
CVE-2020-16042
MEDIUM 6.5

Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a …

CVE-2020-16041
HIGH 8.1

Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed a remote attacker who had compromised the renderer process to obtain potentiall…

CVE-2020-16040
MEDIUM 6.5

Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

CVE-2020-16039
HIGH 8.8

Use after free in extensions in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-16038
HIGH 8.8

Use after free in media in Google Chrome on OS X prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-16037
HIGH 8.8

Use after free in clipboard in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-16036
MEDIUM 6.5

Inappropriate implementation in cookies in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass cookie restrictions via a crafted HTML page.

CVE-2020-16035
HIGH 8.8

Insufficient data validation in cros-disks in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process…

CVE-2020-16034
MEDIUM 4.3

Inappropriate implementation in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a local attacker to bypass policy restrictions via a crafted HTML page.

CVE-2020-16033
MEDIUM 4.3

Inappropriate implementation in WebUSB in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVE-2020-16032
MEDIUM 4.3

Insufficient data validation in sharing in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a c…

CVE-2020-16031
MEDIUM 4.3

Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafte…

CVE-2020-16030
MEDIUM 6.1

Insufficient data validation in Blink in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted…

CVE-2020-16029
HIGH 8.8

Inappropriate implementation in PDFium in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to bypass navigation restrictions via a crafted PDF fil…

CVE-2020-16028
HIGH 8.8

Heap buffer overflow in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-16027
MEDIUM 6.5

Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convinced a user to install a malicious exten…

CVE-2020-16026
HIGH 8.8

Use after free in WebRTC in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-16025
CRITICAL 9.6

Heap buffer overflow in clipboard in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perf…

CVE-2020-16024
CRITICAL 9.6

Heap buffer overflow in UI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a s…

CVE-2020-16023
HIGH 8.8

Use after free in WebCodecs in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-16022
HIGH 8.8

Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall controls via a cr…

CVE-2020-16021
HIGH 7.5

Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to perform OS-level p…

CVE-2020-16020
HIGH 8.8

Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process…

CVE-2020-16019
HIGH 8.8

Inappropriate implementation in filesystem in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process…

CVE-2020-16018
CRITICAL 9.6

Use after free in payments in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a s…

CVE-2020-16017
CRITICAL 9.6

Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perf…

CVE-2020-16016
CRITICAL 9.6

Inappropriate implementation in base in Google Chrome prior to 86.0.4240.193 allowed a remote attacker who had compromised the renderer process to potentially …

CVE-2020-16015
HIGH 8.8

Insufficient data validation in WASM in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

CVE-2020-16014
CRITICAL 9.6

Use after free in PPAPI in Google Chrome prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to potentially perform a sand…

CVE-2020-16013
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

CVE-2020-16012
MEDIUM 4.3

Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVE-2020-17130
MEDIUM 6.5

Microsoft Excel Security Feature Bypass Vulnerability

CVE-2020-17129
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2020-17128
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2020-17127
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2020-17126
MEDIUM 5.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2020-17125
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2020-17124
HIGH 7.8

Microsoft PowerPoint Remote Code Execution Vulnerability

CVE-2020-17123
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2020-17119
MEDIUM 6.5

Microsoft Outlook Information Disclosure Vulnerability

CVE-2020-17067
HIGH 7.8

Microsoft Excel Security Feature Bypass Vulnerability

CVE-2020-17066
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2020-17065
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2020-17064
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2020-17020
LOW 3.3

Microsoft Word Security Feature Bypass Vulnerability

CVE-2020-6557
MEDIUM 6.5

Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVE-2020-16011
CRITICAL 9.6

Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially…

CVE-2020-16010
CRITICAL 9.6

Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially…

CVE-2020-16009
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

CVE-2020-16008
HIGH 8.8

Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC …

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM