Vulnérabilités
Vulnérabilités des apps suivies
11 306 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-20870
HIGH 7.8
Local
Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20869
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacke… |
|
CVE-2026-20868
HIGH 8.8
Réseau
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-20867
HIGH 7.8
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… |
|
CVE-2026-20866
HIGH 7.8
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… |
|
CVE-2026-20865
HIGH 7.8
Local
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20864
HIGH 7.8
Local
Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20863
HIGH 7.0
Local
Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20861
HIGH 7.8
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to ele… |
|
CVE-2026-20860
HIGH 7.8
Local
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… |
|
CVE-2026-20859
HIGH 7.8
Local
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20858
HIGH 7.8
Local
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20857
HIGH 7.8
Local
Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20856
HIGH 8.1
Réseau
Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-20854
HIGH 7.5
Réseau
Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. |
|
CVE-2026-20853
HIGH 7.4
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate… |
|
CVE-2026-20852
HIGH 7.7
Local
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. |
|
CVE-2026-20849
HIGH 7.5
Réseau
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-20848
HIGH 7.5
Réseau
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate priv… |
|
CVE-2026-20844
HIGH 7.4
Local
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. |
|
CVE-2026-20843
HIGH 7.8
Local
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20842
HIGH 7.0
Local
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20840
HIGH 7.8
Local
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. |
|
CVE-2026-20837
HIGH 7.8
Local
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. |
|
CVE-2026-20836
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile… |
|
CVE-2026-20832
HIGH 7.8
Local
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability |
|
CVE-2026-20831
HIGH 7.8
Local
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20826
HIGH 7.8
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an autho… |
|
CVE-2026-20822
HIGH 7.8
Local
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20820
HIGH 7.8
Local
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20817
HIGH 7.8
Local
Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20816
HIGH 7.8
Local
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20815
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz… |
|
CVE-2026-20814
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privile… |
|
CVE-2026-20811
HIGH 7.8
Local
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20809
HIGH 7.8
Local
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20808
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elev… |
|
CVE-2026-20804
HIGH 7.7
Local
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. |
|
CVE-2026-0891
HIGH 8.1
Réseau 1 apps
Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2026-0889
HIGH 7.5
Réseau 1 apps
Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. |
|
CVE-2026-0882
HIGH 8.8
Réseau 1 apps
Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0880
HIGH 8.8
Réseau 1 apps
Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbi… |
|
CVE-2026-0878
HIGH 8.0
Réseau 1 apps
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thu… |
|
CVE-2026-0877
HIGH 8.1
Réseau 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thun… |
|
CVE-2026-20833
HIGH 5.5
Windows Kerberos Information Disclosure Vulnerability |
|
CVE-2026-20830
HIGH 7.0
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability |
|
CVE-2026-20818
HIGH 6.2
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-20810
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-0386
HIGH 7.5
Windows Deployment Services Remote Code Execution Vulnerability |
|
CVE-2024-55414
HIGH 7.8
Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability |