Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

3,490 CVEs affect a tracked app or OS (Medium, Windows). 21 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
3,490
Actively exploited
21
Publication window
2009-07-30 → 2026-09-29

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

3,490 entries Medium Windows Clear all
CVE
CVE-2020-1574
MEDIUM 5.5

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited…

CVE-2020-1503
MEDIUM 5.5

An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability…

CVE-2020-1497
MEDIUM 5.5

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerabilit…

CVE-2020-1493
MEDIUM 5.5

An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached fil…

CVE-2020-1483
MEDIUM 5.0

A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully ex…

CVE-2020-15658
MEDIUM 6.5

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier p…

CVE-2020-15655
MEDIUM 6.5

A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-ori…

CVE-2020-15654
MEDIUM 6.5

When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are …

CVE-2020-15653
MEDIUM 6.5

An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying o…

CVE-2020-15652
MEDIUM 6.5

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content …

CVE-2020-15648
MEDIUM 6.5

Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affec…

CVE-2020-6536
MEDIUM 4.3

Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the content…

CVE-2020-6535
MEDIUM 6.1

Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scrip…

CVE-2020-6531
MEDIUM 4.3

Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTM…

CVE-2020-6529
MEDIUM 4.3

Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data vi…

CVE-2020-6528
MEDIUM 4.3

Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via …

CVE-2020-6527
MEDIUM 4.3

Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML pa…

CVE-2020-6526
MEDIUM 6.5

Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted…

CVE-2020-6521
MEDIUM 6.5

Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from …

CVE-2020-6519
MEDIUM 6.5

Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVE-2020-6516
MEDIUM 4.3

Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVE-2020-6514
MEDIUM 6.5

Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap …

CVE-2020-6511
MEDIUM 6.5

Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVE-2020-6506
MEDIUM 6.5

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted …

CVE-2020-1462
MEDIUM 4.3

An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft E…

CVE-2020-1445
MEDIUM 5.5

An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclos…

CVE-2020-1433
MEDIUM 6.5

An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Information Disclos…

CVE-2020-1342
MEDIUM 5.5

An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose …

CVE-2020-12421
MEDIUM 6.5

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) …

CVE-2020-12418
MEDIUM 6.5

Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affec…

CVE-2020-12405
MEDIUM 5.3

When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects…

CVE-2020-12399
MEDIUM 4.4

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thund…

CVE-2020-14422
MEDIUM · vendor

Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to…

CVE-2020-1242
MEDIUM 5.3

An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnera…

CVE-2020-1229
MEDIUM 4.3

A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlo…

CVE-2020-1220
MEDIUM 6.1

A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) …

CVE-2020-6504
MEDIUM 4.3

Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a cr…

CVE-2020-6503
MEDIUM 6.5

Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information fro…

CVE-2020-6502
MEDIUM 6.5

Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVE-2020-6501
MEDIUM 6.5

Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML pa…

CVE-2020-6500
MEDIUM 6.5

Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) v…

CVE-2020-6499
MEDIUM 6.5

Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppCache security restrictions via a crafte…

CVE-2020-6498
MEDIUM 6.5

Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted HTM…

CVE-2020-6497
MEDIUM 6.5

Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted URI.

CVE-2020-6495
MEDIUM 6.5

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious exten…

CVE-2020-6494
MEDIUM 6.5

Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) vi…

CVE-2011-2863
MEDIUM 6.5

Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process mem…

CVE-2020-13631
MEDIUM · vendor

SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.

CVE-2020-12392
MEDIUM 5.5

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user …

CVE-2020-13434
MEDIUM · vendor

SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM