Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,433 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,433
Actively exploited
21
Publication window
2009-07-30 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,433 entries Medium Windows Clear all
CVE
CVE-2024-11159
MEDIUM 4.3

Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < …

CVE-2024-11117
MEDIUM 4.3

Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass filesystem restrictions via a crafted HT…

CVE-2024-11116
MEDIUM 4.3

Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures …

CVE-2024-11111
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestur…

CVE-2024-11110
MEDIUM 6.5

Inappropriate implementation in Extensions in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Exte…

CVE-2024-10468
MEDIUM 5.3

Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 13…

CVE-2024-10465
MEDIUM 6.5

A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbir…

CVE-2024-10464
MEDIUM 6.5

Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing r…

CVE-2024-10463
MEDIUM 6.5

Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Th…

CVE-2024-10462
MEDIUM 6.5

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird …

CVE-2024-10461
MEDIUM 6.1

In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could al…

CVE-2024-10460
MEDIUM 5.3

The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Fire…

CVE-2024-9287
MEDIUM · vendor

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, all…

CVE-2024-9966
MEDIUM 5.3

Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass content security policy via a crafted H…

CVE-2024-9964
MEDIUM 4.3

Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestur…

CVE-2024-9963
MEDIUM 4.3

Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestu…

CVE-2024-9962
MEDIUM 4.3

Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI ges…

CVE-2024-9958
MEDIUM 4.3

Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML pa…

CVE-2024-44157
MEDIUM 5.5

A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Par…

CVE-2024-43573
MEDIUM · vendor KEV

Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-9398
MEDIUM 5.3

By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that …

CVE-2024-9397
MEDIUM 6.1

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerabilit…

CVE-2024-7022
MEDIUM 4.3

Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chro…

CVE-2024-7020
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chr…

CVE-2024-7019
MEDIUM 4.3

Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

CVE-2023-7282
MEDIUM 4.3

Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinced a user to engage in specific UI gest…

CVE-2023-7281
MEDIUM 4.3

Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

CVE-2024-8909
MEDIUM 4.3

Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Ch…

CVE-2024-8908
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chr…

CVE-2024-8907
MEDIUM 6.1

Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific…

CVE-2024-8906
MEDIUM 4.3

Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

CVE-2024-38222
MEDIUM 6.5

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVE-2024-43487
MEDIUM 6.5

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-38258
MEDIUM 6.5

Windows Remote Desktop Licensing Service Information Disclosure Vulnerability

CVE-2024-38256
MEDIUM 5.5

Windows Kernel-Mode Driver Information Disclosure Vulnerability

CVE-2024-38254
MEDIUM 5.5

Windows Authentication Information Disclosure Vulnerability

CVE-2024-38235
MEDIUM 6.5

Windows Hyper-V Denial of Service Vulnerability

CVE-2024-38234
MEDIUM 6.5

Windows Networking Denial of Service Vulnerability

CVE-2024-38231
MEDIUM 6.5

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

CVE-2024-38230
MEDIUM 6.5

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

CVE-2024-38217
MEDIUM 5.4 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-8394
MEDIUM 6.5

When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vuln…

CVE-2024-8035
MEDIUM 4.3

Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HT…

CVE-2024-8034
MEDIUM 4.3

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted H…

CVE-2024-8033
MEDIUM 4.3

Inappropriate implementation in WebApp Installs in Google Chrome on Windows prior to 128.0.6613.84 allowed an attacker who convinced a user to install a malici…

CVE-2024-7981
MEDIUM 4.3

Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromi…

CVE-2024-7978
MEDIUM 4.3

Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who convinced a user to engage in specific U…

CVE-2024-7976
MEDIUM 4.3

Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromi…

CVE-2024-7975
MEDIUM 4.3

Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (…

CVE-2024-38173
MEDIUM 6.7

Microsoft Outlook Remote Code Execution Vulnerability

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM