Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

7,750 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
7,750
Actively exploited
213
Publication window
2007-08-28 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

7,750 entries Windows Hide N/A Clear all
CVE
CVE-2023-25751
MEDIUM 6.5 1 app

Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially …

CVE-2023-25746
HIGH 8.8 1 app

Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these c…

CVE-2023-25742
MEDIUM 6.5 1 app

When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, T…

CVE-2023-25739
HIGH 8.8 1 app

Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext</code>. Th…

CVE-2023-25738
MEDIUM 6.5 1 app

Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn wo…

CVE-2023-25737
HIGH 8.8 1 app

An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This vulnerability affects Firefox < 110, Th…

CVE-2023-25735
HIGH 8.8 1 app

Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-…

CVE-2023-25734
HIGH 8.1 1 app

After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network …

CVE-2023-25732
HIGH 8.8 1 app

When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated potentially leading …

CVE-2023-25730
MEDIUM 5.4 1 app

A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, result…

CVE-2023-25729
HIGH 8.8 1 app

Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user…

CVE-2023-25728
MEDIUM 6.5 1 app

The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe t…

CVE-2023-23605
HIGH 8.8 1 app

Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of…

CVE-2023-23603
MEDIUM 6.5 1 app

Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Da…

CVE-2023-23602
MEDIUM 6.5 1 app

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to co…

CVE-2023-23601
MEDIUM 6.5 1 app

Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability…

CVE-2023-23599
MEDIUM 6.5 1 app

When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands …

CVE-2023-23598
MEDIUM 6.5 1 app

Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website cou…

CVE-2023-1945
MEDIUM 6.5 1 app

Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunder…

CVE-2023-0767
HIGH 8.8 1 app

An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. …

CVE-2023-0616
MEDIUM 6.5 1 app

If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause T…

CVE-2023-0547
MEDIUM 6.5 1 app

OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird v…

CVE-2023-0430
MEDIUM 6.5 1 app

Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a vali…

CVE-2023-29336
HIGH 7.8 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2023-29325
CRITICAL 8.1

Windows OLE Remote Code Execution Vulnerability

CVE-2023-29324
HIGH 6.5

Windows MSHTML Platform Security Feature Bypass Vulnerability

CVE-2023-28283
CRITICAL 8.1

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVE-2023-28251
HIGH 5.5

Windows Driver Revocation List Security Feature Bypass Vulnerability

CVE-2023-24949
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-24948
HIGH 7.4

Windows Bluetooth Driver Elevation of Privilege Vulnerability

CVE-2023-24947
HIGH 8.8

Windows Bluetooth Driver Remote Code Execution Vulnerability

CVE-2023-24946
HIGH 7.8

Windows Backup Service Elevation of Privilege Vulnerability

CVE-2023-24945
HIGH 5.5

Windows iSCSI Target Service Information Disclosure Vulnerability

CVE-2023-24944
HIGH 6.5

Windows Bluetooth Driver Information Disclosure Vulnerability

CVE-2023-24943
CRITICAL 9.8

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVE-2023-24942
HIGH 7.5

Remote Procedure Call Runtime Denial of Service Vulnerability

CVE-2023-24941
CRITICAL 9.8

Windows Network File System Remote Code Execution Vulnerability

CVE-2023-24940
HIGH 7.5

Windows Pragmatic General Multicast (PGM) Denial of Service Vulnerability

CVE-2023-24939
HIGH 7.5

Server for NFS Denial of Service Vulnerability

CVE-2023-24932
HIGH 6.7

Secure Boot Security Feature Bypass Vulnerability

CVE-2023-24905
HIGH 7.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2023-24903
CRITICAL 8.1

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

CVE-2023-24902
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2023-24901
HIGH 7.5

Windows NFS Portmapper Information Disclosure Vulnerability

CVE-2023-24900
HIGH 5.9

Windows NTLM Security Support Provider Information Disclosure Vulnerability

CVE-2023-24899
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2023-24898
HIGH 7.5

Windows SMB Denial of Service Vulnerability

CVE-2023-29007
HIGH 7.0 1 app

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a specially cra…

CVE-2023-25652
HIGH 7.5 1 app

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by feeding spec…

CVE-2023-27043
MEDIUM 5.3 1 app

The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is ident…