Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

11 325 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2026-42982
HIGH 7.8 Local

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-42975
HIGH 8.0 Réseau adjacent

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-42900
HIGH 8.1 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate pri…

CVE-2026-40400
HIGH 8.0 Réseau

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

CVE-2026-40378
HIGH 7.5 Réseau

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over …

CVE-2026-15308
HIGH 7.5 Réseau 1 apps

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontr…

CVE-2026-43735
HIGH 8.1 Réseau

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6,…

CVE-2026-43731
HIGH 8.8 Réseau

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t…

CVE-2026-43725
HIGH 7.1 Réseau

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visi…

CVE-2026-43724
HIGH 7.8 Local

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS…

CVE-2026-43715
HIGH 8.8 Réseau

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t…

CVE-2026-43705
HIGH 8.8 Réseau

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, v…

CVE-2026-43701
HIGH 7.1 Réseau

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6,…

CVE-2026-12328
HIGH 8.1 Réseau 1 apps

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed eviden…

CVE-2026-12327
HIGH 8.1 Réseau 1 apps

Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corrupt…

CVE-2026-12326
HIGH 8.1 Réseau 1 apps

Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2026-12324
HIGH 7.3 Réseau 1 apps

Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thu…

CVE-2026-12318
HIGH 7.3 Réseau 1 apps

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12317
HIGH 7.5 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12314
HIGH 7.5 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12312
HIGH 7.5 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12310
HIGH 7.5 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12305
HIGH 7.5 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12292
HIGH 8.1 Réseau 1 apps

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140…

CVE-2026-12291
HIGH 8.8 Réseau 1 apps

Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thu…

CVE-2026-12290
HIGH 8.1 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 1…

CVE-2026-12289
HIGH 8.8 Réseau 1 apps

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152…

CVE-2026-8863
HIGH 7.8 Local

Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the bo…

CVE-2026-49160
HIGH 7.5 Réseau

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

CVE-2026-48583
HIGH 7.8 Local

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-48578
HIGH 7.9 Local

Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.

CVE-2026-48576
HIGH 7.9 Local

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48575
HIGH 7.9 Local

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48574
HIGH 7.8 Local

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-48573
HIGH 7.9 Local

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48570
HIGH 7.9 Local

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48568
HIGH 7.9 Local

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48563
HIGH 7.5 Réseau

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47656
HIGH 7.9 Local

Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.

CVE-2026-47654
HIGH 7.5 Réseau

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47653
HIGH 8.8 Réseau

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47652
HIGH 8.2 Local

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

CVE-2026-47648
HIGH 7.0 Local

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-47289
HIGH 8.8 Réseau

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47288
HIGH 7.1 Réseau adjacent

Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.

CVE-2026-45658
HIGH 7.8 Local

Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.

CVE-2026-45656
HIGH 7.8 Local

Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.

CVE-2026-45654
HIGH 7.9 Local

Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-45653
HIGH 7.0 Local

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-45649
HIGH 7.1 Local 3 apps

Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.