Vulnérabilités
Vulnérabilités des apps suivies
227 CVE touchent une app ou un OS suivi (Élevé, Windows). 177 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 227
- Activement exploitées
- 177
- Fenêtre de publication
- 2013-06-26 → 2026-02-10
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-21250
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21248
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21244
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2025-11001
HIGH 7.8
1 app
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… |
|
CVE-2025-59254
HIGH 7.8
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-50154
HIGH 6.5
Microsoft Windows File Explorer Spoofing Vulnerability |
|
CVE-2025-6965
HIGH 7.7
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead… |
|
CVE-2025-49744
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-49730
HIGH 7.8
Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability |
|
CVE-2025-49683
HIGH 7.8
Microsoft Virtual Hard Disk Remote Code Execution Vulnerability |
|
CVE-2025-49677
HIGH 7.0
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-47987
HIGH 7.8
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability |
|
CVE-2025-33073
HIGH 8.8
KEV
Windows SMB Client Elevation of Privilege Vulnerability |
|
CVE-2025-30397
HIGH 7.5
KEV
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2025-26633
HIGH 7.0
KEV
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-24076
HIGH 7.3
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
|
CVE-2025-24071
HIGH 6.5
Microsoft Windows File Explorer Spoofing Vulnerability |
|
CVE-2025-24054
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-21333
HIGH 7.8
KEV
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2024-49138
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38193
HIGH 7.8
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2024-4367
HIGH 8.8
1 app
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Fire… |
|
CVE-2024-21338
HIGH 7.8
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-21320
HIGH 6.5
Windows Themes Spoofing Vulnerability |
|
CVE-2023-44487
HIGH 7.5
KEV
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w… |
|
CVE-2023-29336
HIGH 7.8
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-28293
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-21752
HIGH 7.1
Windows Backup Service Elevation of Privilege Vulnerability |
|
CVE-2019-17026
HIGH 8.8
KEV
1 app
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild a… |
|
CVE-2020-0683
HIGH 7.0
KEV
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2020-0601
HIGH 8.1
KEV
Windows CryptoAPI Spoofing Vulnerability |
|
CVE-2019-1458
HIGH 7.8
KEV
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privil… |
|
CVE-2019-1476
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1405
HIGH 7.8
KEV
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP… |
|
CVE-2019-1347
HIGH 5.7
Windows Denial of Service Vulnerability |
|
CVE-2019-1346
HIGH 5.7
Windows Denial of Service Vulnerability |
|
CVE-2019-1345
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2019-1344
HIGH 5.5
Windows Code Integrity Module Information Disclosure Vulnerability |
|
CVE-2019-1343
HIGH 6.5
Windows Denial of Service Vulnerability |
|
CVE-2019-1322
HIGH 7.0
KEV
Microsoft Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1253
HIGH 7.8
KEV
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1245
HIGH 6.5
DirectWrite Information Disclosure Vulnerability |
|
CVE-2019-1244
HIGH 6.5
DirectWrite Information Disclosure Vulnerability |
|
CVE-2019-1215
HIGH 7.8
KEV
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1184
HIGH 6.7
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1170
HIGH 7.9
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2019-1153
HIGH 5.5
Microsoft Graphics Component Information Disclosure Vulnerability |
|
CVE-2019-1148
HIGH 5.5
Microsoft Graphics Component Information Disclosure Vulnerability |
|
CVE-2019-1125
HIGH 5.6
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2019-11707
HIGH 8.8
KEV
1 app
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware… |