Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,471 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,471
Actively exploited
21
Publication window
2009-07-30 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,471 entries Medium Windows Clear all
CVE
CVE-2022-44698
MEDIUM · vendor KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2022-4195
MEDIUM 4.3

Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass Safe Browsing warnings via a malic…

CVE-2022-4189
MEDIUM 4.3

Insufficient policy enforcement in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension t…

CVE-2022-4188
MEDIUM 4.3

Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote attacker to bypass same origin policy vi…

CVE-2022-4187
MEDIUM 6.5

Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allowed a remote attacker to bypass filesystem restrictions via …

CVE-2022-4186
MEDIUM 4.3

Insufficient validation of untrusted input in Downloads in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious…

CVE-2022-4185
MEDIUM 4.3

Inappropriate implementation in Navigation in Google Chrome on iOS prior to 108.0.5359.71 allowed a remote attacker to spoof the contents of the modal dialogue…

CVE-2022-4184
MEDIUM 4.3

Insufficient policy enforcement in Autofill in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass autofill restrictions via a crafted HTM…

CVE-2022-4183
MEDIUM 4.3

Insufficient policy enforcement in Popup Blocker in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass navigation restrictions via a craf…

CVE-2022-4182
MEDIUM 4.3

Inappropriate implementation in Fenced Frames in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass fenced frame restrictions via a craft…

CVE-2022-41105
MEDIUM 5.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2022-41104
MEDIUM 5.5

Microsoft Excel Security Feature Bypass Vulnerability

CVE-2022-41103
MEDIUM 5.5

Microsoft Word Information Disclosure Vulnerability

CVE-2022-41099
MEDIUM 4.6

BitLocker Security Feature Bypass Vulnerability

CVE-2022-41098
MEDIUM 5.5

Windows GDI+ Information Disclosure Vulnerability

CVE-2022-41097
MEDIUM 6.5

Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability

CVE-2022-41091
MEDIUM 5.4 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2022-41090
MEDIUM 5.9

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

CVE-2022-41086
MEDIUM 6.4

Windows Group Policy Elevation of Privilege Vulnerability

CVE-2022-41060
MEDIUM 5.5

Microsoft Word Information Disclosure Vulnerability

CVE-2022-41055
MEDIUM 5.5

Windows Human Interface Device Information Disclosure Vulnerability

CVE-2022-41049
MEDIUM 5.4 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2022-38015
MEDIUM 6.5

Windows Hyper-V Denial of Service Vulnerability

CVE-2022-3447
MEDIUM 4.3

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacker to spoof the contents of the Omnibox …

CVE-2022-3661
MEDIUM 4.3

Insufficient data validation in Extensions in Google Chrome prior to 107.0.5304.62 allowed a remote attacker who had compromised the renderer process to leak c…

CVE-2022-3660
MEDIUM 4.3

Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 107.0.5304.62 allowed a remote attacker to hide the contents of the Omnib…

CVE-2022-3444
MEDIUM 4.3

Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a craf…

CVE-2022-3443
MEDIUM 4.3

Insufficient data validation in File System API in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass File System restrictions via a craf…

CVE-2022-3318
MEDIUM 4.3

Use after free in ChromeOS Notifications in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to reboot Chrome OS…

CVE-2022-3317
MEDIUM 4.3

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 106.0.5249.62 allowed a remote attacker to bypass navigation restric…

CVE-2022-3316
MEDIUM 4.3

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass security feature via a …

CVE-2022-3314
MEDIUM 6.5

Use after free in logging in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbo…

CVE-2022-3313
MEDIUM 6.5

Incorrect security UI in full screen in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium …

CVE-2022-3312
MEDIUM 4.6

Insufficient validation of untrusted input in VPN in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a local attacker to bypass managed device restric…

CVE-2022-3311
MEDIUM 6.5

Use after free in import in Google Chrome prior to 106.0.5249.62 allowed a remote attacker who had compromised a WebUI process to potentially perform a sandbox…

CVE-2022-3310
MEDIUM 6.5

Insufficient policy enforcement in custom tabs in Google Chrome on Android prior to 106.0.5249.62 allowed an attacker who convinced the user to install an appl…

CVE-2022-3309
MEDIUM 6.5

Use after free in assistant in Google Chrome on ChromeOS prior to 106.0.5249.62 allowed a remote attacker who convinced a user to engage in specific UI gesture…

CVE-2022-3201
MEDIUM 5.4

Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to instal…

CVE-2022-3057
MEDIUM 6.5

Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML p…

CVE-2022-3056
MEDIUM 6.5

Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass content security policy …

CVE-2022-3054
MEDIUM 6.5

Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a craf…

CVE-2022-3053
MEDIUM 4.3

Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted…

CVE-2022-3048
MEDIUM 6.8

Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigat…

CVE-2022-3047
MEDIUM 6.5

Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious exten…

CVE-2022-3044
MEDIUM 6.5

Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to by…

CVE-2022-2861
MEDIUM 6.5

Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extensi…

CVE-2022-2860
MEDIUM 6.5

Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafte…

CVE-2022-2856
MEDIUM 6.5 KEV

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a …

CVE-2021-4189
MEDIUM 5.3

A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the …

CVE-2022-2622
MEDIUM 6.5

Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download res…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM