Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,433 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,433
Actively exploited
21
Publication window
2009-07-30 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,433 entries Medium Windows Clear all
CVE
CVE-2023-3736
MEDIUM 4.3

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 115.0.5790.98 allowed a remote attacker to leak cross-origin data via a crafte…

CVE-2023-3735
MEDIUM 4.3

Inappropriate implementation in Web API Permission Prompts in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate security UI via a cra…

CVE-2023-3734
MEDIUM 4.3

Inappropriate implementation in Picture In Picture in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the O…

CVE-2023-3733
MEDIUM 4.3

Inappropriate implementation in WebApp Installs in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially spoof the contents of the Omni…

CVE-2023-2314
MEDIUM 6.5

Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML…

CVE-2023-2311
MEDIUM 6.5

Insufficient policy enforcement in File System API in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass filesystem restrictions via a cr…

CVE-2022-4926
MEDIUM 6.5

Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a cra…

CVE-2022-4925
MEDIUM 6.5

Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via malicious n…

CVE-2022-4922
MEDIUM 6.5

Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromiu…

CVE-2022-4917
MEDIUM 4.3

Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via…

CVE-2022-4915
MEDIUM 6.5

Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to perform domain spoofing via a crafted HTML…

CVE-2022-4913
MEDIUM 6.5

Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to spoof …

CVE-2022-4911
MEDIUM 6.5

Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML…

CVE-2022-4910
MEDIUM 5.4

Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML…

CVE-2022-4909
MEDIUM 6.3

Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially perform an ASLR bypass via a crafted HTML …

CVE-2022-4908
MEDIUM 4.3

Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak cross-origin data via a crafted HTML p…

CVE-2021-4324
MEDIUM 6.5

Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to read arbitrary files via a malicious file.…

CVE-2021-4323
MEDIUM 6.5

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious…

CVE-2021-4321
MEDIUM 4.3

Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium se…

CVE-2021-4316
MEDIUM 4.3

Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium…

CVE-2023-37207
MEDIUM 6.5

A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have le…

CVE-2023-3497
MEDIUM 4.6

Out of bounds read in Google Security Processor firmware in Google Chrome on Chrome OS prior to 114.0.5735.90 allowed a local attacker to perform denial of ser…

CVE-2023-36539
MEDIUM 5.3

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVE-2023-29545
MEDIUM 6.5

Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the c…

CVE-2023-32208
MEDIUM 5.3

Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113.

CVE-2023-29532
MEDIUM 5.5

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB s…

CVE-2023-33595
MEDIUM 5.5

CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c.

CVE-2023-32212
MEDIUM · vendor

An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderb…

CVE-2023-32211
MEDIUM 6.5

A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVE-2023-32206
MEDIUM 6.5

An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102…

CVE-2023-32205
MEDIUM 4.3

In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attac…

CVE-2023-28164
MEDIUM 6.5

Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability af…

CVE-2023-28163
MEDIUM 6.5

When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those …

CVE-2023-25752
MEDIUM 6.5

When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code…

CVE-2023-25751
MEDIUM 6.5

Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially …

CVE-2023-25742
MEDIUM 6.5

When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, T…

CVE-2023-25738
MEDIUM 6.5

Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn wo…

CVE-2023-25730
MEDIUM 5.4

A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, result…

CVE-2023-25728
MEDIUM 6.5

The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe t…

CVE-2023-23604
MEDIUM 6.5

A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have lead to byp…

CVE-2023-23603
MEDIUM 6.5

Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Da…

CVE-2023-23602
MEDIUM 6.5

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to co…

CVE-2023-23601
MEDIUM 6.5

Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability…

CVE-2023-23599
MEDIUM 6.5

When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands …

CVE-2023-23598
MEDIUM 6.5

Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website cou…

CVE-2023-1945
MEDIUM 6.5

Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunder…

CVE-2023-0616
MEDIUM 6.5

If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause T…

CVE-2023-0547
MEDIUM 6.5

OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird v…

CVE-2023-0430
MEDIUM 6.5

Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a vali…

CVE-2023-2941
MEDIUM 4.3

Inappropriate implementation in Extensions API in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extensio…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM