Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

663 CVEs affect a tracked app or OS (Critical, macOS). 22 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
663
Actively exploited
22
Publication window
2008-01-16 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

663 entries Critical macOS Clear all
CVE
CVE-2024-54465
CRITICAL 9.8

A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.

CVE-2024-44299
CRITICAL 9.8

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unex…

CVE-2024-44242
CRITICAL 9.8

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unex…

CVE-2024-44241
CRITICAL 9.8

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to cause unex…

CVE-2023-47100
CRITICAL · vendor

[Apple Perl] Multiple issues in Perl

CVE-2024-9369
CRITICAL 9.6

Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an o…

CVE-2024-44206
CRITICAL 9.3

An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, t…

CVE-2024-7024
CRITICAL 9.6

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML…

CVE-2024-44148
CRITICAL 10.0

This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.

CVE-2024-44146
CRITICAL 10.0

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.

CVE-2024-7971
CRITICAL 9.6 KEV

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security s…

CVE-2023-7012
CRITICAL 9.6

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app …

CVE-2023-4860
CRITICAL 9.6

Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially …

CVE-2019-25154
CRITICAL 9.6

Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted H…

CVE-2024-6779
CRITICAL 9.6

Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML…

CVE-2024-38476
CRITICAL 9.8

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend application…

CVE-2024-5274
CRITICAL 9.6 KEV

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…

CVE-2024-4947
CRITICAL 9.6 KEV

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chr…

CVE-2024-4671
CRITICAL 9.6 KEV

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a …

CVE-2024-27280
CRITICAL 9.8

A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods …

CVE-2024-4558
CRITICAL 9.6

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2024-3157
CRITICAL 9.6

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentiall…

CVE-2024-21413
CRITICAL 9.8 KEV

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2024-1284
CRITICAL 9.8

Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro…

CVE-2024-1283
CRITICAL 9.8

Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.…

CVE-2023-5841
CRITICAL 9.1

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing…

CVE-2024-0808
CRITICAL 9.8

Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chro…

CVE-2023-50643
CRITICAL 9.8

An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments compon…

CVE-2023-6345
CRITICAL 9.6 KEV

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a s…

CVE-2019-13690
CRITICAL 9.6

Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalation via a …

CVE-2022-4924
CRITICAL 9.6

Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the renderer process to potentially perform a san…

CVE-2022-4920
CRITICAL 9.6

Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to poten…

CVE-2023-33150
CRITICAL 9.6

Microsoft Office Security Feature Bypass Vulnerability

CVE-2023-2136
CRITICAL 9.6 KEV

Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a s…

CVE-2023-1529
CRITICAL 9.8

Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious…

CVE-2023-23397
CRITICAL 9.8 KEV

Microsoft Outlook Elevation of Privilege Vulnerability

CVE-2023-21716
CRITICAL 9.8

Microsoft Word Remote Code Execution Vulnerability

CVE-2022-4135
CRITICAL 9.6 KEV

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform …

CVE-2022-3075
CRITICAL 9.6 KEV

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially…

CVE-2022-2587
CRITICAL 9.8

Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corru…

CVE-2022-2010
CRITICAL 9.3

Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially pe…

CVE-2022-1853
CRITICAL 9.6

Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVE-2022-1312
CRITICAL 9.6

Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perf…

CVE-2022-1309
CRITICAL 9.6

Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape vi…

CVE-2022-0977
CRITICAL 9.6

Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user inte…

CVE-2022-0973
CRITICAL 9.6

Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-0790
CRITICAL 9.6

Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to poten…

CVE-2022-0466
CRITICAL 9.6

Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convinced a user to install a malicious exte…

CVE-2022-0452
CRITICAL 9.6

Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pag…

CVE-2022-0290
CRITICAL 9.6

Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pa…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM