Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,433 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,433
Actively exploited
21
Publication window
2009-07-30 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,433 entries Medium Windows Clear all
CVE
CVE-2024-38213
MEDIUM · vendor KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-7005
MEDIUM 4.3

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in…

CVE-2024-7004
MEDIUM 4.3

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in…

CVE-2024-7003
MEDIUM 4.3

Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures …

CVE-2024-7001
MEDIUM 4.3

Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures t…

CVE-2024-6999
MEDIUM 4.3

Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures …

CVE-2024-6995
MEDIUM 4.7

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in speci…

CVE-2024-7529
MEDIUM 6.5

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability …

CVE-2024-7526
MEDIUM · vendor

ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnera…

CVE-2024-7518
MEDIUM 6.5

Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affect…

CVE-2024-38103
MEDIUM 5.9

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

CVE-2024-38156
MEDIUM 6.1

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2024-5500
MEDIUM 6.5

Inappropriate implementation in Sign-In in Google Chrome prior to 1.3.36.351 allowed a remote attacker to bypass navigation restrictions via a crafted HTML pag…

CVE-2024-3175
MEDIUM 6.3

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chro…

CVE-2024-2884
MEDIUM 6.5

Out of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HT…

CVE-2023-7013
MEDIUM 4.7

Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof security UI via a crafted H…

CVE-2023-7011
MEDIUM 6.5

Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL…

CVE-2020-36765
MEDIUM 6.5

Insufficient policy enforcement in Navigation in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML pag…

CVE-2024-6777
MEDIUM 6.5

Use after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to potentially …

CVE-2024-38020
MEDIUM 6.5

Microsoft Outlook Spoofing Vulnerability

CVE-2024-6614
MEDIUM · vendor

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 …

CVE-2024-6613
MEDIUM · vendor

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 …

CVE-2024-6612
MEDIUM · vendor

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CS…

CVE-2024-6610
MEDIUM · vendor

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen m…

CVE-2024-6608
MEDIUM · vendor

It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulner…

CVE-2024-6603
MEDIUM · vendor

In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerabilit…

CVE-2024-6601
MEDIUM · vendor

A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < …

CVE-2024-6600
MEDIUM 6.3

Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private s…

CVE-2024-39684
MEDIUM · vendor

Github: CVE-2024-39684 TenCent RapidJSON Elevation of Privilege Vulnerability

CVE-2024-38517
MEDIUM · vendor

Github: CVE-2024-38517 TenCent RapidJSON Elevation of Privilege Vulnerability

CVE-2024-38093
MEDIUM 4.3

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2024-38082
MEDIUM 4.7

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2024-5843
MEDIUM 6.5

Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chr…

CVE-2024-5840
MEDIUM 6.5

Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromi…

CVE-2024-5839
MEDIUM 6.5

Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a…

CVE-2024-30096
MEDIUM 5.5

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2024-30076
MEDIUM 6.8

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2024-30069
MEDIUM 4.7

Windows Remote Access Connection Manager Information Disclosure Vulnerability

CVE-2024-30067
MEDIUM 5.5

Winlogon Elevation of Privilege Vulnerability

CVE-2024-30066
MEDIUM 5.5

Winlogon Elevation of Privilege Vulnerability

CVE-2024-30065
MEDIUM 5.5

Windows Themes Denial of Service Vulnerability

CVE-2024-30063
MEDIUM 6.7

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

CVE-2024-5693
MEDIUM 6.1

Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. T…

CVE-2024-5692
MEDIUM 6.5

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.ur…

CVE-2024-5691
MEDIUM 4.7

By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions…

CVE-2024-5690
MEDIUM · vendor

By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulner…

CVE-2024-4950
MEDIUM 6.5

Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestu…

CVE-2024-4949
MEDIUM 6.5

Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

CVE-2024-4948
MEDIUM 6.5

Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrom…

CVE-2024-4772
MEDIUM 5.9

An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM