Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,433 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,433
Actively exploited
21
Publication window
2009-07-30 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,433 entries Medium Windows Clear all
CVE
CVE-2024-4769
MEDIUM 5.9

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses…

CVE-2024-4768
MEDIUM 6.1

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Fi…

CVE-2024-4767
MEDIUM 4.3

If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disa…

CVE-2024-30050
MEDIUM · vendor

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-4559
MEDIUM 6.5

Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

CVE-2024-4060
MEDIUM 6.5

Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrom…

CVE-2024-4059
MEDIUM 6.5

Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chromium secur…

CVE-2024-3914
MEDIUM 6.5

Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

CVE-2024-3847
MEDIUM 6.1

Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML…

CVE-2024-3846
MEDIUM 4.3

Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gesture…

CVE-2024-3845
MEDIUM 4.3

Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML pa…

CVE-2024-3844
MEDIUM 4.3

Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extens…

CVE-2024-3843
MEDIUM 4.3

Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Ch…

CVE-2024-3841
MEDIUM 6.1

Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged …

CVE-2024-3839
MEDIUM 6.5

Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory v…

CVE-2024-3838
MEDIUM 5.5

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform…

CVE-2024-3861
MEDIUM · vendor

If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability…

CVE-2024-3860
MEDIUM 6.2

An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vul…

CVE-2024-3859
MEDIUM · vendor

On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulner…

CVE-2024-3516
MEDIUM 6.5

Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

CVE-2024-3515
MEDIUM 6.5

Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro…

CVE-2024-30370
MEDIUM 4.3

RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected i…

CVE-2024-29057
MEDIUM 4.3

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2024-26247
MEDIUM 4.7

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVE-2024-2631
MEDIUM 4.3

Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium…

CVE-2024-2630
MEDIUM 6.5

Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chrom…

CVE-2024-2629
MEDIUM 4.3

Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium securi…

CVE-2024-2628
MEDIUM 4.3

Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium…

CVE-2024-2626
MEDIUM 6.5

Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML p…

CVE-2024-2611
MEDIUM · vendor

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox…

CVE-2024-2610
MEDIUM 6.1

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability a…

CVE-2024-2609
MEDIUM 6.1

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerabi…

CVE-2024-2605
MEDIUM · vendor

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows …

CVE-2023-5388
MEDIUM 6.5

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data…

CVE-2024-1676
MEDIUM 5.4

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chr…

CVE-2024-1672
MEDIUM 5.4

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via…

CVE-2024-1671
MEDIUM 6.5

Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafte…

CVE-2024-1556
MEDIUM 6.5

The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue onl…

CVE-2024-1551
MEDIUM · vendor

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well …

CVE-2024-1550
MEDIUM · vendor

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedl…

CVE-2024-1549
MEDIUM 6.1

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and un…

CVE-2024-1548
MEDIUM · vendor

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing…

CVE-2024-1547
MEDIUM 6.5

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL sh…

CVE-2024-21377
MEDIUM 5.5

Windows DNS Information Disclosure Vulnerability

CVE-2024-21362
MEDIUM 5.5

Windows Kernel Security Feature Bypass Vulnerability

CVE-2024-21356
MEDIUM 6.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2024-21344
MEDIUM 5.9

Windows Network Address Translation (NAT) Denial of Service Vulnerability

CVE-2024-21343
MEDIUM 5.9

Windows Network Address Translation (NAT) Denial of Service Vulnerability

CVE-2024-21341
MEDIUM 6.8

Windows Kernel Remote Code Execution Vulnerability

CVE-2024-21340
MEDIUM 4.6

Windows Kernel Information Disclosure Vulnerability

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM