Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,459 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,459
Actively exploited
21
Publication window
2009-07-30 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,459 entries Medium Windows Clear all
CVE
CVE-2022-3266
MEDIUM 5.5

An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thun…

CVE-2022-3034
MEDIUM 4.3

When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. However, …

CVE-2022-3032
MEDIUM 6.5

When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remot…

CVE-2022-38472
MEDIUM 6.5

An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This cou…

CVE-2022-36318
MEDIUM 5.3

When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox E…

CVE-2022-36314
MEDIUM 5.5

When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the opera…

CVE-2022-34479
MEDIUM 6.5

A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusi…

CVE-2022-34478
MEDIUM 6.5

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a us…

CVE-2022-34472
MEDIUM 4.3

If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being…

CVE-2022-31744
MEDIUM 6.5

An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. …

CVE-2022-31742
MEDIUM 6.5

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles …

CVE-2022-31738
MEDIUM 6.5

When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofin…

CVE-2022-2226
MEDIUM 6.5

An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, th…

CVE-2022-29916
MEDIUM 6.5

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the bro…

CVE-2022-29914
MEDIUM 6.5

When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This v…

CVE-2022-29913
MEDIUM 6.5

The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerabili…

CVE-2022-29912
MEDIUM 6.1

Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91…

CVE-2022-29911
MEDIUM 6.1

An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>…

CVE-2022-28286
MEDIUM 5.4

Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnera…

CVE-2022-28285
MEDIUM 6.5

When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this c…

CVE-2022-28282
MEDIUM 6.5

By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution and then re…

CVE-2022-26386
MEDIUM 6.5

Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to downl…

CVE-2022-26383
MEDIUM 4.3

When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Fir…

CVE-2022-22760
MEDIUM 6.5

When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-scrip…

CVE-2022-22754
MEDIUM 6.5

If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new …

CVE-2022-22748
MEDIUM 6.5

Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulner…

CVE-2022-22747
MEDIUM 6.5

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed t…

CVE-2022-22746
MEDIUM 5.9

A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only…

CVE-2022-22745
MEDIUM 6.5

Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefo…

CVE-2022-22743
MEDIUM 4.3

When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mod…

CVE-2022-22742
MEDIUM 6.5

When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerabil…

CVE-2022-22739
MEDIUM 6.5

Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affects Firefox ESR < 91.…

CVE-2022-1834
MEDIUM 6.5

When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displaye…

CVE-2022-1520
MEDIUM 4.3

When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encr…

CVE-2022-1197
MEDIUM 5.4

When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet r…

CVE-2022-1196
MEDIUM 6.5

After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnera…

CVE-2022-1097
MEDIUM 6.5

<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-fre…

CVE-2021-4126
MEDIUM 6.5

When receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message layer, for example a message footer added by a mailing list …

CVE-2022-44698
MEDIUM · vendor KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2022-4195
MEDIUM 4.3

Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass Safe Browsing warnings via a malic…

CVE-2022-4189
MEDIUM 4.3

Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension t…

CVE-2022-4188
MEDIUM 4.3

Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote attacker to bypass same origin policy vi…

CVE-2022-4187
MEDIUM 6.5

Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allowed a remote attacker to bypass filesystem restrictions via …

CVE-2022-4186
MEDIUM 4.3

Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious…

CVE-2022-4185
MEDIUM 4.3

Inappropriate implementation in Navigation in Google Chrome on iOS prior to 108.0.5359.71 allowed a remote attacker to spoof the contents of the modal dialogue…

CVE-2022-4184
MEDIUM 4.3

Insufficient policy enforcement in Autofill in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass autofill restrictions via a crafted HTM…

CVE-2022-4183
MEDIUM 4.3

Insufficient policy enforcement in Popup Blocker in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass navigation restrictions via a craf…

CVE-2022-4182
MEDIUM 4.3

Inappropriate implementation in Fenced Frames in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass fenced frame restrictions via a craft…

CVE-2022-41105
MEDIUM 5.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2022-41104
MEDIUM 5.5

Microsoft Excel Security Feature Bypass Vulnerability

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM