Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

11 306 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2026-21513
HIGH 8.8 KEV

MSHTML Framework Security Feature Bypass Vulnerability

CVE-2026-21510
HIGH 8.8 KEV

Windows Shell Security Feature Bypass Vulnerability

CVE-2026-21508
HIGH 7.0

Windows Storage Elevation of Privilege Vulnerability

CVE-2026-21255
HIGH 8.8

Windows Hyper-V Security Feature Bypass Vulnerability

CVE-2026-21253
HIGH 7.0

Mailslot File System Elevation of Privilege Vulnerability

CVE-2026-21251
HIGH 7.8

Cluster Client Failover (CCF) Elevation of Privilege Vulnerability

CVE-2026-21250
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-21249
HIGH 3.3

Windows NTLM Spoofing Vulnerability

CVE-2026-21248
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2026-21247
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2026-21246
HIGH 7.8

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2026-21245
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-21244
HIGH 7.3

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2026-21243
HIGH 7.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2026-21242
HIGH 7.0

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVE-2026-21241
HIGH 7.0

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-21240
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-21239
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-21238
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-21237
HIGH 7.0

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVE-2026-21236
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-21235
HIGH 7.3

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2026-21234
HIGH 7.0

Windows Connected Devices Platform Service Elevation of Privilege Vulnerability

CVE-2026-21232
HIGH 7.8

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2026-21231
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-21222
HIGH 5.5

Windows Kernel Information Disclosure Vulnerability

CVE-2026-20846
HIGH 7.5

GDI+ Denial of Service Vulnerability

CVE-2023-2804
HIGH 6.5

Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo

CVE-2025-11002
HIGH 7.8 Local 1 apps

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte…

CVE-2024-44238
HIGH 7.8 Local

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be able to corrupt coproce…

CVE-2026-21221
HIGH 7.0 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz…

CVE-2026-20941
HIGH 7.8 Local

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVE-2026-20940
HIGH 7.8 Local

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-20938
HIGH 7.8 Local

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVE-2026-20934
HIGH 7.5 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20931
HIGH 8.0 Réseau adjacent

External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.

CVE-2026-20929
HIGH 7.5 Réseau

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

CVE-2026-20926
HIGH 7.5 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20924
HIGH 7.8 Local

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20923
HIGH 7.8 Local

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20922
HIGH 7.8 Local

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

CVE-2026-20921
HIGH 7.5 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20920
HIGH 7.8 Local

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-20919
HIGH 7.5 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv…

CVE-2026-20918
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20877
HIGH 7.8 Local

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-20875
HIGH 7.5 Réseau

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

CVE-2026-20874
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20873
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele…

CVE-2026-20871
HIGH 7.8 Local

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.