Annual recap
App security · 2023
2023 recap indexed by Appaloosa Scout: 1,676 CVEs published during the year on tracked apps, 49 added to the CISA KEV catalog (exploited in the wild), 13 apps affected by at least one KEV.
- CVE indexed this year
- 1,676
- CISA KEV added
- 49
- Tracked apps affected
- 13
Severity distribution
CRITICAL
132
HIGH
1,306
MEDIUM
231
LOW
7
Top 10 KEVs of the year
Sorted by CVSS severity. “Apps” counts tracked catalog apps: many KEVs are OS-level and legitimately show 0.
| CVE | Severity | Apps | Added to KEV | Description |
|---|---|---|---|---|
|
CVE-2023-23397
3 apps
|
CRITICAL 9.8 | 3 | 2023-03-14 | Microsoft Outlook Elevation of Privilege Vulnerability |
|
CVE-2023-6345
2 apps
|
CRITICAL 9.6 | 2 | 2023-11-30 | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to pot… |
|
CVE-2023-2136
2 apps
|
CRITICAL 9.6 | 2 | 2023-04-21 | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to pot… |
|
CVE-2023-5217
6 apps
|
HIGH 8.8 | 6 | 2023-10-02 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to pote… |
|
CVE-2023-4863
4 apps
|
HIGH 8.8 | 4 | 2023-09-13 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of b… |
|
CVE-2023-35311
3 apps
|
HIGH 8.8 | 3 | 2023-07-11 | Microsoft Outlook Security Feature Bypass Vulnerability |
|
CVE-2023-3079
2 apps
|
HIGH 8.8 | 2 | 2023-06-07 | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafte… |
|
CVE-2023-2033
2 apps
|
HIGH 8.8 | 2 | 2023-04-17 | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafte… |
|
CVE-2022-3038
2 apps
|
HIGH 8.8 | 2 | 2023-03-30 | Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption … |
|
CVE-2023-42917
0 apps
|
HIGH 8.8 | 0 | 2023-12-04 | A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14… |
Top vendors by KEV this year
- 1 Google LLC 7 KEV · 1 apps
- 2 Microsoft Corporation 4 KEV · 3 apps
- 3 Mozilla 3 KEV · 3 apps
- 4 Microsoft 3 KEV · 1 apps
- 5 Microsoft Office 3 KEV · 1 apps
- 6 Adobe 2 KEV · 1 apps
- 7 Adobe Acrobat Reader 2 KEV · 1 apps
- 8 win.rar GmbH 1 KEV · 1 apps
Most affected apps
Google Chrome
winget:Google.Chrome
No open vuln.
Chrome
com.google.Chrome
No open vuln.
Mozilla Thunderbird
winget:Mozilla.Thunderbird
No open vuln.
Mozilla Firefox
winget:Mozilla.Firefox
No open vuln.
Office
winget:Microsoft.Office
No open vuln.
Microsoft Office
brew:cask:microsoft-office
No open vuln.
Adobe Acrobat Reader (64-bit)
winget:Adobe.Acrobat.Reader.64-bit
No open vuln.
Microsoft Outlook
com.microsoft.Outlook
No open vuln.
Adobe Acrobat Reader
brew:cask:adobe-acrobat-reader
No open vuln.
WinRAR
winget:RARLab.WinRAR
No open vuln.
Methodology
KEV: added to the CISA catalog during the year (kev_added_date). CVE: NVD publication date. Apps: those indexed in Scout at query time; the history evolves as new mappings are added.