Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,539 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,539
Actively exploited
214
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,539 entries Windows Clear all
CVE
CVE-2021-29949
HIGH 7.8 1 app

When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distri…

CVE-2021-29948
LOW 2.5 1 app

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replac…

CVE-2021-29946
HIGH 8.8 1 app

Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc hea…

CVE-2021-29945
MEDIUM 6.5 1 app

The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32…

CVE-2021-24002
HIGH 8.8 1 app

When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary c…

CVE-2021-23999
HIGH 8.8 1 app

If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should…

CVE-2021-23998
MEDIUM 6.5 1 app

Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox E…

CVE-2021-23995
HIGH 8.8 1 app

When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been expl…

CVE-2021-23994
HIGH 8.8 1 app

A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10,…

CVE-2021-23993
MEDIUM 6.5 1 app

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a sub…

CVE-2021-23992
MEDIUM 4.3 1 app

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key,…

CVE-2021-23991
MEDIUM 6.8 1 app

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet b…

CVE-2021-1675
HIGH 7.8 KEV

Windows Print Spooler Remote Code Execution Vulnerability

CVE-2021-33742
CRITICAL 7.5 KEV

Windows MSHTML Platform Remote Code Execution Vulnerability

CVE-2021-33739
HIGH 8.4 KEV

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2021-31977
HIGH 8.6

Windows Hyper-V Denial of Service Vulnerability

CVE-2021-31976
HIGH 7.5

Server for NFS Information Disclosure Vulnerability

CVE-2021-31975
HIGH 7.5

Server for NFS Information Disclosure Vulnerability

CVE-2021-31974
HIGH 7.5

Server for NFS Denial of Service Vulnerability

CVE-2021-31973
HIGH 7.8

Windows GPSVC Elevation of Privilege Vulnerability

CVE-2021-31972
HIGH 5.5

Event Tracing for Windows Information Disclosure Vulnerability

CVE-2021-31971
HIGH 6.8

Windows HTML Platforms Security Feature Bypass Vulnerability

CVE-2021-31970
HIGH 5.5

Windows TCP/IP Driver Security Feature Bypass Vulnerability

CVE-2021-31969
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2021-31968
HIGH 7.5

Windows Remote Desktop Services Denial of Service Vulnerability

CVE-2021-31962
HIGH 9.4

Kerberos AppContainer Security Feature Bypass Vulnerability

CVE-2021-31960
HIGH 5.5

Windows Bind Filter Driver Information Disclosure Vulnerability

CVE-2021-31959
CRITICAL 6.4

Scripting Engine Memory Corruption Vulnerability

CVE-2021-31958
HIGH 7.5

Windows NTLM Elevation of Privilege Vulnerability

CVE-2021-31956
HIGH 7.8 KEV

Windows NTFS Elevation of Privilege Vulnerability

CVE-2021-31955
HIGH 5.5 KEV

Windows Kernel Information Disclosure Vulnerability

CVE-2021-31954
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2021-31953
HIGH 7.8

Windows Filter Manager Elevation of Privilege Vulnerability

CVE-2021-31952
HIGH 7.8

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

CVE-2021-31951
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2021-31201
HIGH 5.2 KEV

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVE-2021-31199
HIGH 5.2 KEV

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVE-2021-26414
HIGH 4.8

Windows DCOM Server Security Feature Bypass

CVE-2021-3426
MEDIUM 5.7 1 app

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server co…

CVE-2021-31208
HIGH 7.8

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-31205
HIGH 6.5

Windows SMB Client Security Feature Bypass Vulnerability

CVE-2021-31194
CRITICAL 8.8

OLE Automation Remote Code Execution Vulnerability

CVE-2021-31193
HIGH 7.8

Windows SSDP Service Elevation of Privilege Vulnerability

CVE-2021-31192
HIGH 7.8

Windows Media Foundation Core Remote Code Execution Vulnerability

CVE-2021-31191
HIGH 5.5

Windows Projected File System FS Filter Driver Information Disclosure Vulnerability

CVE-2021-31190
HIGH 7.8

Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability

CVE-2021-31188
HIGH 7.8

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2021-31187
HIGH 7.8

Windows WalletService Elevation of Privilege Vulnerability

CVE-2021-31186
HIGH 7.4

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

CVE-2021-31185
HIGH 5.5

Windows Desktop Bridge Denial of Service Vulnerability