Vulnerabilities
Tracked app vulnerabilities
3,490 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.
- Matching CVEs
- 3,490
- Actively exploited
- 21
- Publication window
- 2009-07-30 → 2026-09-29
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2021-43546
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefo… |
|
CVE-2021-43545
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0,… |
|
CVE-2021-43543
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects… |
|
CVE-2021-43542
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability aff… |
|
CVE-2021-43541
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunder… |
|
CVE-2021-43538
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock… |
|
CVE-2021-43536
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < … |
|
CVE-2021-43528
MEDIUM 6.5
Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level… |
|
CVE-2021-38509
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top a… |
|
CVE-2021-38508
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could hav… |
|
CVE-2021-38507
The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HT… |
|
CVE-2021-38506
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on… |
|
CVE-2021-38505
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it… |
|
CVE-2021-38004
Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
|
CVE-2021-38000
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a m… |
|
CVE-2021-37999
Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new brow… |
|
CVE-2021-42288
MEDIUM 5.7
Windows Hello Security Feature Bypass Vulnerability |
|
CVE-2021-42284
MEDIUM 6.8
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2021-42280
MEDIUM 5.5
Windows Feedback Hub Elevation of Privilege Vulnerability |
|
CVE-2021-42279
MEDIUM 4.2
Chakra Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-42277
MEDIUM 5.5
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability |
|
CVE-2021-42274
MEDIUM 6.8
Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability |
|
CVE-2021-41379
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2021-41371
MEDIUM 4.4
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
|
CVE-2021-41368
Microsoft Access Remote Code Execution Vulnerability |
|
CVE-2021-41351
MEDIUM 4.3
Microsoft Edge (Chrome based) Spoofing on IE Mode |
|
CVE-2021-38631
MEDIUM 4.4
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
|
CVE-2021-38502
MEDIUM 5.9
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted mes… |
|
CVE-2021-38497
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusi… |
|
CVE-2021-38492
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in In… |
|
CVE-2018-6125
Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information … |
|
CVE-2021-37996
Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a m… |
|
CVE-2021-37995
Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents… |
|
CVE-2021-37994
Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted… |
|
CVE-2021-37990
Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app. |
|
CVE-2021-37989
Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content security policy via a crafted HTML page. |
|
CVE-2021-40472
Microsoft Excel Information Disclosure Vulnerability |
|
CVE-2021-37976
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from proces… |
|
CVE-2021-37971
Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a c… |
|
CVE-2021-37968
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted H… |
|
CVE-2021-37967
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process … |
|
CVE-2021-37966
Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (U… |
|
CVE-2021-37965
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted H… |
|
CVE-2021-37963
Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page. |
|
CVE-2021-37958
Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to inject scripts or HTML into a privile… |
|
CVE-2021-30630
Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-o… |
|
CVE-2021-38669
MEDIUM 6.4
Microsoft Edge (Chromium-based) Tampering Vulnerability |
|
CVE-2021-38637
MEDIUM 5.5
Windows Storage Information Disclosure Vulnerability |
|
CVE-2021-38636
MEDIUM 5.5
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability |
|
CVE-2021-38635
MEDIUM 5.5
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.