Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,490 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,490
Actively exploited
21
Publication window
2009-07-30 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,490 entries Medium Windows Clear all
CVE
CVE-2020-17131
MEDIUM 4.2

Chakra Scripting Engine Memory Corruption Vulnerability

CVE-2020-17130
MEDIUM 6.5

Microsoft Excel Security Feature Bypass Vulnerability

CVE-2020-17126
MEDIUM 5.5

Microsoft Excel Information Disclosure Vulnerability

CVE-2020-17119
MEDIUM 6.5

Microsoft Outlook Information Disclosure Vulnerability

CVE-2020-26966
MEDIUM 6.5

Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; res…

CVE-2020-26965
MEDIUM 6.5

Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when…

CVE-2020-26961
MEDIUM 6.5

When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver.…

CVE-2020-26958
MEDIUM 6.1

Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a…

CVE-2020-26956
MEDIUM 6.1

In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox …

CVE-2020-26953
MEDIUM 4.3

It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or other…

CVE-2020-26951
MEDIUM 6.1

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of expl…

CVE-2020-17054
MEDIUM 4.2

Chakra Scripting Engine Memory Corruption Vulnerability

CVE-2020-17048
MEDIUM 4.2

Chakra Scripting Engine Memory Corruption Vulnerability

CVE-2020-6557
MEDIUM 6.5

Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVE-2020-15989
MEDIUM 5.5

Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory v…

CVE-2020-15988
MEDIUM 6.3

Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker who convinced the user to open files t…

CVE-2020-15986
MEDIUM 6.5

Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-15985
MEDIUM 6.5

Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVE-2020-15984
MEDIUM 6.5

Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to spoof the contents of the Omnibox (URL ba…

CVE-2020-15982
MEDIUM 6.5

Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process…

CVE-2020-15981
MEDIUM 6.5

Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory vi…

CVE-2020-15977
MEDIUM 6.5

Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information fr…

CVE-2020-15973
MEDIUM 6.5

Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to install a malicious extension …

CVE-2020-16949
MEDIUM 4.7

<p>A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who success…

CVE-2020-15646
MEDIUM 5.9

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attack…

CVE-2020-15677
MEDIUM 6.1

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original s…

CVE-2020-15676
MEDIUM 6.1

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attack…

CVE-2020-6571
MEDIUM 4.3

Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a cr…

CVE-2020-6570
MEDIUM 4.3

Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC…

CVE-2020-6569
MEDIUM 6.3

Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit hea…

CVE-2020-6568
MEDIUM 6.5

Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restriction…

CVE-2020-6567
MEDIUM 6.5

Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navig…

CVE-2020-6566
MEDIUM 6.5

Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVE-2020-6565
MEDIUM 6.5

Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) …

CVE-2020-6564
MEDIUM 6.5

Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a…

CVE-2020-6563
MEDIUM 6.5

Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive …

CVE-2020-6562
MEDIUM 6.5

Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVE-2020-6561
MEDIUM 6.5

Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafte…

CVE-2020-6560
MEDIUM 6.5

Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVE-2020-6558
MEDIUM 6.5

Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a craft…

CVE-2020-6547
MEDIUM 6.5

Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML…

CVE-2020-6538
MEDIUM 6.5

Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HT…

CVE-2020-15966
MEDIUM 4.3

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension…

CVE-2020-15959
MEDIUM 4.3

Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain po…

CVE-2020-1224
MEDIUM 5.5

<p>An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerabi…

CVE-2020-1180
MEDIUM 4.2

<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memo…

CVE-2020-1172
MEDIUM 4.2

<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memo…

CVE-2020-1057
MEDIUM 4.2

<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memo…

CVE-2020-16884
MEDIUM 4.2

<p>A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory.…

CVE-2020-0878
MEDIUM 4.2 KEV

<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way th…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM