Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,441 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,441
Actively exploited
21
Publication window
2009-07-30 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,441 entries Medium Windows Clear all
CVE
CVE-2023-0704
MEDIUM 6.5

Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings v…

CVE-2023-0700
MEDIUM 6.5

Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (UR…

CVE-2023-0697
MEDIUM 6.5

Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the secu…

CVE-2023-0141
MEDIUM 4.3

Insufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (C…

CVE-2023-0140
MEDIUM 6.5

Inappropriate implementation in in File System API in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass file system restricti…

CVE-2023-0139
MEDIUM 6.5

Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass download restric…

CVE-2023-0133
MEDIUM 6.5

Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main origin permis…

CVE-2023-0132
MEDIUM 6.5

Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to force acceptance of a per…

CVE-2023-0131
MEDIUM 6.5

Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download restrictions via a …

CVE-2023-0130
MEDIUM 6.5

Inappropriate implementation in in Fullscreen API in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to spoof the contents of the Omn…

CVE-2022-4025
MEDIUM 4.3

Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafte…

CVE-2022-3863
MEDIUM 6.1

Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

CVE-2022-0801
MEDIUM 6.1

Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass XSS preventions via a crafted HTML page.…

CVE-2022-0337
MEDIUM 6.5

Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive inf…

CVE-2021-21200
MEDIUM 5.4

Out of bounds read in WebUI Settings in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTM…

CVE-2022-46880
MEDIUM 6.5

A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on December 13t…

CVE-2022-46875
MEDIUM 6.5

The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue onl…

CVE-2022-45420
MEDIUM 6.5

Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user …

CVE-2022-45418
MEDIUM 6.1

If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user con…

CVE-2022-45416
MEDIUM 6.5

Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have…

CVE-2022-45411
MEDIUM 6.1

Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies in…

CVE-2022-45410
MEDIUM · vendor

When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This …

CVE-2022-45408
MEDIUM 6.5

Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in…

CVE-2022-45405
MEDIUM 6.5

Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This …

CVE-2022-45404
MEDIUM 6.5

Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification promp…

CVE-2022-45403
MEDIUM 6.5

Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range …

CVE-2022-42929
MEDIUM 6.5

If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending…

CVE-2022-40960
MEDIUM 6.5

Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash. This vul…

CVE-2022-40959
MEDIUM 6.5

During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted su…

CVE-2022-40958
MEDIUM 6.5

By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies fro…

CVE-2022-40957
MEDIUM 6.5

Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affects Firefox on ARM…

CVE-2022-40956
MEDIUM 6.1

When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability …

CVE-2022-3266
MEDIUM 5.5

An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thun…

CVE-2022-3034
MEDIUM 4.3

When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. However, …

CVE-2022-3032
MEDIUM 6.5

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remot…

CVE-2022-38472
MEDIUM 6.5

An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This cou…

CVE-2022-36318
MEDIUM 5.3

When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox E…

CVE-2022-36314
MEDIUM 5.5

When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the opera…

CVE-2022-34479
MEDIUM 6.5

A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusi…

CVE-2022-34478
MEDIUM 6.5

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a us…

CVE-2022-34472
MEDIUM 4.3

If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being…

CVE-2022-31744
MEDIUM 6.5

An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. …

CVE-2022-31742
MEDIUM 6.5

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles …

CVE-2022-31738
MEDIUM 6.5

When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofin…

CVE-2022-2226
MEDIUM 6.5

An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, th…

CVE-2022-29916
MEDIUM 6.5

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the bro…

CVE-2022-29914
MEDIUM 6.5

When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This v…

CVE-2022-29913
MEDIUM 6.5

The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerabili…

CVE-2022-29912
MEDIUM 6.1

Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91…

CVE-2022-29911
MEDIUM 6.1

An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM