Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,434 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,434
Actively exploited
21
Publication window
2009-07-30 → 2026-09-28

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,434 entries Medium Windows Clear all
CVE
CVE-2023-2941
MEDIUM 4.3

Inappropriate implementation in Extensions API in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extensio…

CVE-2023-2940
MEDIUM 6.5

Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to …

CVE-2023-2938
MEDIUM 4.3

Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process t…

CVE-2023-2937
MEDIUM 4.3

Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process t…

CVE-2023-2468
MEDIUM 4.3

Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to …

CVE-2023-2467
MEDIUM 4.3

Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a c…

CVE-2023-2466
MEDIUM 4.3

Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafte…

CVE-2023-2465
MEDIUM 4.3

Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chro…

CVE-2023-2464
MEDIUM 4.3

Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extens…

CVE-2023-2463
MEDIUM 4.3

Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnib…

CVE-2023-2462
MEDIUM 4.3

Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page…

CVE-2023-2459
MEDIUM 6.5

Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML …

CVE-2023-27043
MEDIUM · vendor

The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is ident…

CVE-2023-1823
MEDIUM 6.5

Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML pa…

CVE-2023-1822
MEDIUM 6.5

Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chro…

CVE-2023-1821
MEDIUM 6.5

Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL…

CVE-2023-1819
MEDIUM 6.5

Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTM…

CVE-2023-1817
MEDIUM 6.5

Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a…

CVE-2023-1816
MEDIUM 6.5

Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a …

CVE-2023-1814
MEDIUM 6.5

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a…

CVE-2023-1813
MEDIUM 6.5

Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to…

CVE-2023-24880
MEDIUM · vendor KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2023-1236
MEDIUM 4.3

Inappropriate implementation in Internals in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to spoof the origin of an iframe via a crafted HTML…

CVE-2023-1235
MEDIUM 6.3

Type confusion in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to potentially exploit he…

CVE-2023-1234
MEDIUM 4.3

Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to perform domain spoofing via a crafted H…

CVE-2023-1233
MEDIUM 4.3

Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious exte…

CVE-2023-1232
MEDIUM 4.3

Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to obtain potentially sensitive informatio…

CVE-2023-1231
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to potentially spoof the contents of the …

CVE-2023-1230
MEDIUM 4.3

Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malici…

CVE-2023-1229
MEDIUM 4.3

Inappropriate implementation in Permission prompts in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a cr…

CVE-2023-1228
MEDIUM 4.3

Insufficient policy enforcement in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a…

CVE-2023-1226
MEDIUM 6.5

Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass content security policy via a c…

CVE-2023-1225
MEDIUM 4.3

Insufficient policy enforcement in Navigation in Google Chrome on iOS prior to 111.0.5563.64 allowed a remote attacker to bypass same origin policy via a craft…

CVE-2023-1224
MEDIUM 4.3

Insufficient policy enforcement in Web Payments API in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a c…

CVE-2023-1223
MEDIUM 4.3

Insufficient policy enforcement in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to leak cross-origin data via a crafte…

CVE-2023-1221
MEDIUM 4.3

Insufficient policy enforcement in Extensions API in Google Chrome prior to 111.0.5563.64 allowed an attacker who convinced a user to install a malicious exten…

CVE-2023-1217
MEDIUM 6.5

Stack buffer overflow in Crash reporting in Google Chrome on Windows prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process …

CVE-2023-21714
MEDIUM 5.5

Microsoft Office Information Disclosure Vulnerability

CVE-2023-21699
MEDIUM 5.3

Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability

CVE-2023-21697
MEDIUM 6.2

Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability

CVE-2023-21694
MEDIUM 6.8

Windows Fax Service Remote Code Execution Vulnerability

CVE-2023-21693
MEDIUM 5.7

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

CVE-2023-21687
MEDIUM 5.5

HTTP.sys Information Disclosure Vulnerability

CVE-2023-0704
MEDIUM 6.5

Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings v…

CVE-2023-0700
MEDIUM 6.5

Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (UR…

CVE-2023-0697
MEDIUM 6.5

Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the secu…

CVE-2023-0141
MEDIUM 4.3

Insufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (C…

CVE-2023-0140
MEDIUM 6.5

Inappropriate implementation in in File System API in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass file system restricti…

CVE-2023-0139
MEDIUM 6.5

Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass download restric…

CVE-2023-0133
MEDIUM 6.5

Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main origin permis…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM