Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,433 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,433
Actively exploited
21
Publication window
2009-07-30 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,433 entries Medium Windows Clear all
CVE
CVE-2025-11716
MEDIUM 6.5

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thu…

CVE-2025-11712
MEDIUM 6.1

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a…

CVE-2025-11711
MEDIUM 6.5

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefo…

CVE-2025-59502
MEDIUM · vendor

Remote Procedure Call Denial of Service Vulnerability

CVE-2025-10536
MEDIUM 6.2

Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140…

CVE-2025-10532
MEDIUM 6.5

Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird…

CVE-2025-10531
MEDIUM 5.4

Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

CVE-2025-10529
MEDIUM 6.5

Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

CVE-2025-54901
MEDIUM 5.5

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2025-9867
MEDIUM 5.4

Inappropriate implementation in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTM…

CVE-2025-9865
MEDIUM 5.4

Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific…

CVE-2025-9181
MEDIUM 6.5

Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, T…

CVE-2025-8881
MEDIUM 6.5

Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI ge…

CVE-2025-53736
MEDIUM 6.8

Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2025-53779
MEDIUM · vendor

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2025-8583
MEDIUM 4.3

Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (…

CVE-2025-8582
MEDIUM 4.3

Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL …

CVE-2025-8581
MEDIUM 4.3

Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gest…

CVE-2025-8580
MEDIUM 4.3

Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (…

CVE-2025-8579
MEDIUM 4.3

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific…

CVE-2025-8577
MEDIUM 4.3

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific…

CVE-2025-8033
MEDIUM 6.5

The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in…

CVE-2025-8027
MEDIUM 6.5

On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulner…

CVE-2025-46789
MEDIUM 6.5

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

CVE-2025-48812
MEDIUM 5.5

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2025-49760
MEDIUM · vendor

Windows Storage Spoofing Vulnerability

CVE-2025-6557
MEDIUM 5.4

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specifi…

CVE-2025-6556
MEDIUM 5.4

Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTM…

CVE-2025-6555
MEDIUM 5.4

Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (…

CVE-2025-5986
MEDIUM 6.5

A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompti…

CVE-2025-2884
MEDIUM 6.6

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with…

CVE-2025-47171
MEDIUM 6.7

Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

CVE-2025-5283
MEDIUM 5.4

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2025-5281
MEDIUM 5.4

Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted …

CVE-2025-5067
MEDIUM 5.4

Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Ch…

CVE-2025-5066
MEDIUM 6.5

Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specifi…

CVE-2025-5065
MEDIUM 6.5

Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTM…

CVE-2025-5064
MEDIUM 5.4

Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted …

CVE-2025-4664
MEDIUM 4.3

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page.…

CVE-2025-3932
MEDIUM 6.5

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accesse…

CVE-2025-4051
MEDIUM 6.3

Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestur…

CVE-2025-4092
MEDIUM 6.5

Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-4089
MEDIUM 5.1

Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading t…

CVE-2025-4088
MEDIUM 6.5

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invo…

CVE-2025-4087
MEDIUM 4.8

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This cou…

CVE-2025-4084
MEDIUM 5.7

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leadi…

CVE-2025-4082
MEDIUM 5.9

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate…

CVE-2025-1292
MEDIUM 6.7

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence …

CVE-2025-1122
MEDIUM 6.7

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and …

CVE-2025-3523
MEDIUM 6.4

When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering ove…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM