Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,490 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,490
Actively exploited
21
Publication window
2009-07-30 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,490 entries Medium Windows Clear all
CVE
CVE-2021-33760
MEDIUM 5.5

Media Foundation Information Disclosure Vulnerability

CVE-2021-33757
MEDIUM 5.3

Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability

CVE-2021-33755
MEDIUM 6.3

Windows Hyper-V Denial of Service Vulnerability

CVE-2021-33745
MEDIUM 6.5

Windows DNS Server Denial of Service Vulnerability

CVE-2021-33744
MEDIUM 5.3

Windows Secure Kernel Mode Security Feature Bypass Vulnerability

CVE-2021-31961
MEDIUM 6.1

Windows InstallService Elevation of Privilege Vulnerability

CVE-2021-29957
MEDIUM 4.3

If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indi…

CVE-2021-29956
MEDIUM 4.3

OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master pass…

CVE-2021-29951
MEDIUM 6.5

The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop th…

CVE-2021-29945
MEDIUM 6.5

The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32…

CVE-2021-23998
MEDIUM 6.5

Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox E…

CVE-2021-23993
MEDIUM 6.5

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a sub…

CVE-2021-23992
MEDIUM 4.3

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key,…

CVE-2021-23991
MEDIUM 6.8

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet b…

CVE-2021-30540
MEDIUM 6.5

Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML pag…

CVE-2021-30539
MEDIUM 5.4

Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy v…

CVE-2021-30538
MEDIUM 4.3

Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy v…

CVE-2021-30537
MEDIUM 4.3

Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page.

CVE-2021-30534
MEDIUM 6.5

Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a craft…

CVE-2021-30533
MEDIUM 6.5 KEV

Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafte…

CVE-2021-30532
MEDIUM 4.3

Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy v…

CVE-2021-30531
MEDIUM 6.5

Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy v…

CVE-2021-3426
MEDIUM 5.7

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server co…

CVE-2021-31178
MEDIUM 5.5

Microsoft Office Information Disclosure Vulnerability

CVE-2021-31174
MEDIUM 5.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2021-21229
MEDIUM 6.5

Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML pa…

CVE-2021-21228
MEDIUM 4.3

Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension …

CVE-2021-21222
MEDIUM 6.5

Heap buffer overflow in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to bypass site isolation v…

CVE-2021-21221
MEDIUM 6.5

Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to…

CVE-2021-21219
MEDIUM 5.5

Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory v…

CVE-2021-21218
MEDIUM 5.5

Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory v…

CVE-2021-21217
MEDIUM 5.5

Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory v…

CVE-2021-21216
MEDIUM 6.5

Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVE-2021-21215
MEDIUM 6.5

Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVE-2021-21212
MEDIUM 6.5

Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowed a remote attacker to potentially compromise WiFi connecti…

CVE-2021-21210
MEDIUM 6.5

Inappropriate implementation in Network in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially access local UDP ports via a crafted HT…

CVE-2021-21209
MEDIUM 6.5

Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVE-2021-21208
MEDIUM 6.5

Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain spoofing vi…

CVE-2021-28456
MEDIUM 5.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2021-28312
MEDIUM · vendor

Windows NTFS Denial of Service Vulnerability

CVE-2021-23984
MEDIUM 6.5

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, …

CVE-2021-23982
MEDIUM 6.5

Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on …

CVE-2020-7463
MEDIUM 5.5

In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handli…

CVE-2021-26892
MEDIUM 6.2

Windows Extensible Firmware Interface Security Feature Bypass Vulnerability

CVE-2021-26886
MEDIUM 6.1

User Profile Service Denial of Service Vulnerability

CVE-2021-26884
MEDIUM 5.5

Windows Media Photo Codec Information Disclosure Vulnerability

CVE-2021-26869
MEDIUM 5.5

Windows ActiveX Installer Service Information Disclosure Vulnerability

CVE-2021-24107
MEDIUM 5.5

Windows Event Tracing Information Disclosure Vulnerability

CVE-2021-21189
MEDIUM 4.3

Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HT…

CVE-2021-21187
MEDIUM 4.3

Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform domain spoofing via IDN homographs v…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM