Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

15,658 CVEs affect a tracked app or OS (all severities, all platforms). 286 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
15,658
Actively exploited
286
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

15,658 entries Hide N/A Clear all
CVE
CVE-2021-43545
MEDIUM 6.5 1 app

Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0,…

CVE-2021-43543
MEDIUM 6.1 1 app

Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects…

CVE-2021-43542
MEDIUM 6.5 1 app

Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability aff…

CVE-2021-43541
MEDIUM 6.5 1 app

When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunder…

CVE-2021-43539
HIGH 8.8 1 app

Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers…

CVE-2021-43538
MEDIUM 4.3 1 app

By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock…

CVE-2021-43537
HIGH 8.8 1 app

An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulne…

CVE-2021-43536
MEDIUM 6.5 1 app

Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < …

CVE-2021-43535
HIGH 8.8 1 app

A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable…

CVE-2021-43534
HIGH 8.8 1 app

Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory c…

CVE-2021-43528
MEDIUM 6.5 1 app

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level…

CVE-2021-38510
HIGH 8.8 1 app

The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: Thi…

CVE-2021-38509
MEDIUM 4.3 1 app

Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top a…

CVE-2021-38508
MEDIUM 4.3 1 app

By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could hav…

CVE-2021-38507
MEDIUM 6.5 1 app

The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HT…

CVE-2021-38506
MEDIUM 4.3 1 app

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on…

CVE-2021-38505
MEDIUM 6.5 1 app

Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it…

CVE-2021-38504
HIGH 8.8 1 app

When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption a…

CVE-2021-38503
CRITICAL 10.0 1 app

The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the …

CVE-2021-24041
CRITICAL 9.8 1 app

A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-o…

CVE-2021-30351
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30337
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30336
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30335
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30303
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30293
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30289
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30283
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30282
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30279
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30278
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30276
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30275
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30274
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30273
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30272
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30271
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30270
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30269
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30268
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30267
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-30262
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-1918
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-1894
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-0971
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-0970
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-0969
MEDIUM

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-0968
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-0967
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-0966
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.