Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,750 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,750
Actively exploited
213
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,750 entries Windows Hide N/A Clear all
CVE
CVE-2023-32022
HIGH 7.6

Windows Server Service Security Feature Bypass Vulnerability

CVE-2023-32021
HIGH 7.1

Windows SMB Witness Service Security Feature Bypass Vulnerability

CVE-2023-32020
HIGH 5.6

Windows DNS Spoofing Vulnerability

CVE-2023-32019
HIGH 4.7

Windows Kernel Information Disclosure Vulnerability

CVE-2023-32018
HIGH 7.8

Windows Hello Remote Code Execution Vulnerability

CVE-2023-32017
HIGH 7.8

Microsoft PostScript Printer Driver Remote Code Execution Vulnerability

CVE-2023-32016
HIGH 5.5

Windows Installer Information Disclosure Vulnerability

CVE-2023-32015
CRITICAL 9.8

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVE-2023-32014
CRITICAL 9.8

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVE-2023-32013
CRITICAL 5.3

Windows Hyper-V Denial of Service Vulnerability

CVE-2023-32012
HIGH 7.8

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2023-32011
HIGH 7.5

Windows iSCSI Discovery Service Denial of Service Vulnerability

CVE-2023-32010
HIGH 7.0

Windows Bus Filter Driver Elevation of Privilege Vulnerability

CVE-2023-32009
HIGH 8.8

Windows Collaborative Translation Framework Elevation of Privilege Vulnerability

CVE-2023-32008
HIGH 7.8

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

CVE-2023-29373
HIGH 8.8

Microsoft ODBC Driver Remote Code Execution Vulnerability

CVE-2023-29372
HIGH 8.8

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVE-2023-29371
HIGH 7.8

Windows GDI Elevation of Privilege Vulnerability

CVE-2023-29370
HIGH 7.8

Windows Media Remote Code Execution Vulnerability

CVE-2023-29369
HIGH 6.5

Remote Procedure Call Runtime Denial of Service Vulnerability

CVE-2023-29368
HIGH 7.0

Windows Filtering Platform Elevation of Privilege Vulnerability

CVE-2023-29367
HIGH 7.8

iSCSI Target WMI Provider Remote Code Execution Vulnerability

CVE-2023-29366
HIGH 7.8

Windows Geolocation Service Remote Code Execution Vulnerability

CVE-2023-29365
HIGH 7.8

Windows Media Remote Code Execution Vulnerability

CVE-2023-29364
HIGH 7.0

Windows Authentication Elevation of Privilege Vulnerability

CVE-2023-29363
CRITICAL 9.8

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVE-2023-29362
HIGH 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2023-29361
HIGH 7.0

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-29360
HIGH 8.4 KEV

Microsoft Streaming Service Elevation of Privilege Vulnerability

CVE-2023-29359
HIGH 7.8

GDI Elevation of Privilege Vulnerability

CVE-2023-29358
HIGH 7.8

Windows GDI Elevation of Privilege Vulnerability

CVE-2023-29355
HIGH 5.3

DHCP Server Service Information Disclosure Vulnerability

CVE-2023-29352
HIGH 6.5

Windows Remote Desktop Security Feature Bypass Vulnerability

CVE-2023-29351
HIGH 8.1

Windows Group Policy Elevation of Privilege Vulnerability

CVE-2023-29346
HIGH 7.8

NTFS Elevation of Privilege Vulnerability

CVE-2023-24938
HIGH 6.5

Windows CryptoAPI Denial of Service Vulnerability

CVE-2023-24937
HIGH 6.5

Windows CryptoAPI Denial of Service Vulnerability

CVE-2023-33595
MEDIUM 5.5 1 app

CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c.

CVE-2023-32215
HIGH 8.8 1 app

Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing Team repor…

CVE-2023-32213
HIGH 8.8 1 app

When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird…

CVE-2023-32212
MEDIUM 4.3 1 app

An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderb…

CVE-2023-32211
MEDIUM 6.5 1 app

A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVE-2023-32207
HIGH 8.8 1 app

A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefo…

CVE-2023-32206
MEDIUM 6.5 1 app

An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102…

CVE-2023-32205
MEDIUM 4.3 1 app

In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attac…

CVE-2023-28176
HIGH 8.8 1 app

Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort…

CVE-2023-28164
MEDIUM 6.5 1 app

Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability af…

CVE-2023-28163
MEDIUM 6.5 1 app

When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those …

CVE-2023-28162
HIGH 8.8 1 app

While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash.…

CVE-2023-25752
MEDIUM 6.5 1 app

When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code…