Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,433 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,433
Actively exploited
21
Publication window
2009-07-30 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,433 entries Medium Windows Clear all
CVE
CVE-2023-5169
MEDIUM 6.5

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable…

CVE-2023-4909
MEDIUM 4.3

Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML pag…

CVE-2023-4908
MEDIUM 4.3

Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML pa…

CVE-2023-4907
MEDIUM 4.3

Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTM…

CVE-2023-4906
MEDIUM 4.3

Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTM…

CVE-2023-4905
MEDIUM 4.3

Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromi…

CVE-2023-4904
MEDIUM 4.3

Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a c…

CVE-2023-4903
MEDIUM 4.3

Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a craf…

CVE-2023-4902
MEDIUM 4.3

Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium…

CVE-2023-4901
MEDIUM 4.3

Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML p…

CVE-2023-4900
MEDIUM 4.3

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a…

CVE-2023-36761
MEDIUM 6.5 KEV

Microsoft Word Information Disclosure Vulnerability

CVE-2023-4581
MEDIUM 4.3

Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their pot…

CVE-2023-4580
MEDIUM · vendor

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability …

CVE-2023-4578
MEDIUM 6.5

When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function coul…

CVE-2023-4577
MEDIUM 6.5

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could pot…

CVE-2023-4575
MEDIUM 6.5

When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simul…

CVE-2023-4574
MEDIUM 6.5

When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simu…

CVE-2023-4573
MEDIUM 6.5

When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exp…

CVE-2023-4764
MEDIUM 6.5

Incorrect security UI in BFCache in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafte…

CVE-2023-40217
MEDIUM · vendor

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HT…

CVE-2022-48566
MEDIUM 5.9

An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variab…

CVE-2022-48564
MEDIUM 6.5

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property Li…

CVE-2023-4367
MEDIUM 6.5

Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious exten…

CVE-2023-4365
MEDIUM 4.3

Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. …

CVE-2023-4364
MEDIUM 4.3

Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTM…

CVE-2023-4363
MEDIUM 4.3

Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via…

CVE-2023-4361
MEDIUM 5.3

Inappropriate implementation in Autofill in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to bypass Autofill restrictions via a cra…

CVE-2023-4360
MEDIUM 4.3

Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chro…

CVE-2023-4359
MEDIUM 5.3

Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 116.0.5845.96 allowed a remote attacker to potentially spoof elements of the secu…

CVE-2023-4350
MEDIUM 6.5

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of th…

CVE-2023-38898
MEDIUM 5.3

An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by th…

CVE-2023-38254
MEDIUM 6.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2023-36914
MEDIUM 5.5

Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability

CVE-2023-36913
MEDIUM 6.5

Microsoft Message Queuing Information Disclosure Vulnerability

CVE-2023-36909
MEDIUM 6.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2023-36908
MEDIUM 6.5

Windows Hyper-V Information Disclosure Vulnerability

CVE-2023-36907
MEDIUM 5.5

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2023-36906
MEDIUM 5.5

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2023-36905
MEDIUM 5.5

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

CVE-2023-36893
MEDIUM 6.5

Microsoft Outlook Spoofing Vulnerability

CVE-2023-36889
MEDIUM 5.5

Windows Group Policy Security Feature Bypass Vulnerability

CVE-2023-35384
MEDIUM 5.4

Windows HTML Platforms Security Feature Bypass Vulnerability

CVE-2023-35377
MEDIUM 6.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2023-35376
MEDIUM 6.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2022-4955
MEDIUM 6.5

Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to b…

CVE-2023-3740
MEDIUM 4.3

Insufficient validation of untrusted input in Themes in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially serve malicious content t…

CVE-2023-3739
MEDIUM 6.3

Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code …

CVE-2023-3738
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (C…

CVE-2023-3737
MEDIUM 4.3

Inappropriate implementation in Notifications in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to spoof the contents of media notifications vi…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM