Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,433 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,433
Actively exploited
21
Publication window
2009-07-30 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,433 entries Medium Windows Clear all
CVE
CVE-2025-3522
MEDIUM 6.3

Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird a…

CVE-2025-2830
MEDIUM 6.3

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when t…

CVE-2025-31334
MEDIUM 6.8

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR v…

CVE-2025-3074
MEDIUM 5.4

Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Ch…

CVE-2025-3073
MEDIUM 5.4

Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestur…

CVE-2025-3072
MEDIUM 5.4

Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI ges…

CVE-2025-3071
MEDIUM 5.4

Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI ges…

CVE-2025-3070
MEDIUM 6.5

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via …

CVE-2025-3031
MEDIUM 6.5

An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbird 137.

CVE-2025-3028
MEDIUM 6.5

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firef…

CVE-2025-26695
MEDIUM 5.3

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested emai…

CVE-2025-1923
MEDIUM 4.3

Inappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious exte…

CVE-2025-1922
MEDIUM 4.3

Inappropriate implementation in Selection in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker who convinced a user to engage in specif…

CVE-2025-1921
MEDIUM 6.5

Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a c…

CVE-2025-1917
MEDIUM 4.3

Inappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a crafted HT…

CVE-2025-1938
MEDIUM 6.5

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption a…

CVE-2025-1935
MEDIUM 4.3

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR…

CVE-2025-1934
MEDIUM 6.5

It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was no…

CVE-2025-0996
MEDIUM 5.4

Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of the Omnibox (U…

CVE-2025-0451
MEDIUM 6.3

Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI …

CVE-2025-0445
MEDIUM 5.4

Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

CVE-2025-0444
MEDIUM 6.3

Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrom…

CVE-2025-1019
MEDIUM 4.3

The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. …

CVE-2025-1018
MEDIUM 5.3

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential sp…

CVE-2025-1015
MEDIUM 5.4

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malici…

CVE-2025-1013
MEDIUM 6.5

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vu…

CVE-2025-0510
MEDIUM 6.5

Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vu…

CVE-2025-0448
MEDIUM 4.3

Inappropriate implementation in Compositing in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (…

CVE-2025-0446
MEDIUM 4.3

Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gest…

CVE-2025-0442
MEDIUM 6.5

Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestur…

CVE-2025-0441
MEDIUM 6.5

Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially sensitive information fro…

CVE-2025-0440
MEDIUM 6.5

Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HT…

CVE-2025-0439
MEDIUM 6.5

Race in Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing …

CVE-2025-0435
MEDIUM 6.5

Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HT…

CVE-2025-21357
MEDIUM 6.7

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2025-0243
MEDIUM 5.1

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption a…

CVE-2025-0242
MEDIUM 6.5

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bug…

CVE-2025-0240
MEDIUM 4.0

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability w…

CVE-2025-0239
MEDIUM 4.0

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Fi…

CVE-2025-0238
MEDIUM 5.3

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability …

CVE-2025-0237
MEDIUM 5.4

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal bein…

CVE-2024-49065
MEDIUM 5.5

Microsoft Office Remote Code Execution Vulnerability

CVE-2024-11708
MEDIUM 6.5

Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 an…

CVE-2024-11706
MEDIUM 6.5

A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed o…

CVE-2024-11701
MEDIUM 4.3

The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible sp…

CVE-2024-11696
MEDIUM 5.4

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an i…

CVE-2024-11695
MEDIUM 5.4

A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This …

CVE-2024-11694
MEDIUM 6.1

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the W…

CVE-2024-11692
MEDIUM 4.3

An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability…

CVE-2024-11612
MEDIUM 6.5

7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected i…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM