Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,433 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,433
Actively exploited
21
Publication window
2009-07-30 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,433 entries Medium Windows Clear all
CVE
CVE-2024-21339
MEDIUM 6.4

Windows USB Generic Parent Driver Remote Code Execution Vulnerability

CVE-2024-21304
MEDIUM 4.1

Trusted Compute Base Elevation of Privilege Vulnerability

CVE-2024-20684
MEDIUM 6.5

Windows Hyper-V Denial of Service Vulnerability

CVE-2024-0814
MEDIUM 6.5

Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (…

CVE-2024-0811
MEDIUM 4.3

Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extensio…

CVE-2024-0810
MEDIUM 4.3

Insufficient policy enforcement in DevTools in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension t…

CVE-2024-0809
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML p…

CVE-2024-0805
MEDIUM 4.3

Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain nam…

CVE-2024-0753
MEDIUM · vendor

In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunder…

CVE-2024-0749
MEDIUM 4.3

A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firef…

CVE-2024-0747
MEDIUM 6.5

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy…

CVE-2024-0746
MEDIUM · vendor

A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunde…

CVE-2024-0742
MEDIUM 4.3

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent …

CVE-2024-0741
MEDIUM · vendor

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox…

CVE-2024-0333
MEDIUM 5.3

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious…

CVE-2023-3742
MEDIUM 6.8

Insufficient policy enforcement in ADB in Google Chrome on ChromeOS prior to 114.0.5735.90 allowed a local attacker to bypass device policy restrictions via ph…

CVE-2023-6860
MEDIUM · vendor

The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affe…

CVE-2023-6857
MEDIUM 5.3

When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Uni…

CVE-2023-50762
MEDIUM 4.3

When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text w…

CVE-2023-50761
MEDIUM 4.3

The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare t…

CVE-2023-6507
MEDIUM 6.1

An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. …

CVE-2023-6512
MEDIUM 6.5

Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe…

CVE-2023-6511
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML p…

CVE-2023-6209
MEDIUM · vendor

Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. T…

CVE-2023-6206
MEDIUM · vendor

The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact t…

CVE-2023-6205
MEDIUM · vendor

It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability…

CVE-2023-6204
MEDIUM · vendor

On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on t…

CVE-2023-5859
MEDIUM 4.3

Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local H…

CVE-2023-5858
MEDIUM 4.3

Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML …

CVE-2023-5853
MEDIUM 4.3

Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromi…

CVE-2023-5851
MEDIUM 4.3

Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. …

CVE-2023-5850
MEDIUM 4.3

Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Ch…

CVE-2023-5480
MEDIUM 6.1

Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Ch…

CVE-2023-5732
MEDIUM 6.5

An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affect…

CVE-2023-5727
MEDIUM 6.5

The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. …

CVE-2023-5726
MEDIUM 4.3

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. …

CVE-2023-5725
MEDIUM · vendor

A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulner…

CVE-2023-5721
MEDIUM 4.3

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This …

CVE-2023-5487
MEDIUM 6.5

Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to…

CVE-2023-5486
MEDIUM 4.3

Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium…

CVE-2023-5485
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML p…

CVE-2023-5484
MEDIUM 6.5

Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chr…

CVE-2023-5483
MEDIUM 6.5

Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML …

CVE-2023-5481
MEDIUM 6.5

Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chro…

CVE-2023-5479
MEDIUM 6.5

Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extensio…

CVE-2023-5478
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (…

CVE-2023-5477
MEDIUM 4.3

Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted…

CVE-2023-5475
MEDIUM 6.5

Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to b…

CVE-2023-5473
MEDIUM 6.3

Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap c…

CVE-2023-5171
MEDIUM 6.5

During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potent…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM