Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,770 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,770
Actively exploited
214
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,770 entries Windows Hide N/A Clear all
CVE
CVE-2023-35349
CRITICAL 9.8

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2023-29348
HIGH 7.5

Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability

CVE-2023-5217
HIGH 8.8 KEV 2 apps

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap…

CVE-2023-5176
CRITICAL 9.8 1 app

Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume tha…

CVE-2023-5174
CRITICAL 9.8 1 app

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free a…

CVE-2023-5171
MEDIUM 6.5 1 app

During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potent…

CVE-2023-5169
MEDIUM 6.5 1 app

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable…

CVE-2023-5168
CRITICAL 9.8 1 app

A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable …

CVE-2023-4863
HIGH 8.8 KEV 1 app

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write v…

CVE-2023-38162
HIGH 7.5

DHCP Server Service Denial of Service Vulnerability

CVE-2023-38161
HIGH 7.8

Windows GDI Elevation of Privilege Vulnerability

CVE-2023-38160
HIGH 5.5

Windows TCP/IP Information Disclosure Vulnerability

CVE-2023-38152
HIGH 5.3

DHCP Server Service Information Disclosure Vulnerability

CVE-2023-38150
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-38149
HIGH 7.5

Windows TCP/IP Denial of Service Vulnerability

CVE-2023-38148
CRITICAL 8.8

Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

CVE-2023-38147
HIGH 8.8

Windows Miracast Wireless Display Remote Code Execution Vulnerability

CVE-2023-38146
HIGH 8.8

Windows Themes Remote Code Execution Vulnerability

CVE-2023-38144
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-38143
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-38142
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-38141
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-38140
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2023-38139
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-36805
HIGH 7.0

Windows MSHTML Platform Security Feature Bypass Vulnerability

CVE-2023-36804
HIGH 7.8

Windows GDI Elevation of Privilege Vulnerability

CVE-2023-36803
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2023-36802
HIGH 7.8 KEV

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CVE-2023-36801
HIGH 5.3

DHCP Server Service Information Disclosure Vulnerability

CVE-2023-35355
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-4585
HIGH 8.8 1 app

Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume tha…

CVE-2023-4584
HIGH 8.8 1 app

Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence…

CVE-2023-4583
HIGH 7.5 1 app

When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been dis…

CVE-2023-4582
HIGH 8.8 1 app

Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory…

CVE-2023-4581
MEDIUM 4.3 1 app

Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their pot…

CVE-2023-4580
MEDIUM 6.5 1 app

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability …

CVE-2023-4578
MEDIUM 6.5 1 app

When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function coul…

CVE-2023-4577
MEDIUM 6.5 1 app

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could pot…

CVE-2023-4576
HIGH 8.6 1 app

On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that…

CVE-2023-4575
MEDIUM 6.5 1 app

When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simul…

CVE-2023-4574
MEDIUM 6.5 1 app

When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simu…

CVE-2023-4573
MEDIUM 6.5 1 app

When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exp…

CVE-2023-40217
MEDIUM 5.3 1 app

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HT…

CVE-2023-38831
HIGH 7.8 KEV 1 app

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because …

CVE-2023-41105
HIGH 7.5 1 app

An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly…

CVE-2022-48566
MEDIUM 5.9 1 app

An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variab…

CVE-2022-48565
CRITICAL 9.8 1 app

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoi…

CVE-2022-48564
MEDIUM 6.5 1 app

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property Li…

CVE-2022-48560
HIGH 7.5 1 app

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

CVE-2023-38898
MEDIUM 5.3 1 app

An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by th…