Vulnérabilités
Vulnérabilités des apps suivies
15 629 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-43403
MEDIUM 5.5
Local
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26. An app m… |
|
CVE-2026-1837
HIGH 7.5
Réseau
A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized un… |
|
CVE-2025-59375
MEDIUM 7.5
[Apple libexpat] Processing a maliciously crafted file may lead to a denial-of-service |
|
CVE-2026-21533
HIGH 7.8
KEV
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
|
CVE-2026-21525
MEDIUM 6.2
KEV
Windows Remote Access Connection Manager Denial of Service Vulnerability |
|
CVE-2026-21519
HIGH 7.8
KEV
Desktop Window Manager Elevation of Privilege Vulnerability |
|
CVE-2026-21513
HIGH 8.8
KEV
MSHTML Framework Security Feature Bypass Vulnerability |
|
CVE-2026-21510
HIGH 8.8
KEV
Windows Shell Security Feature Bypass Vulnerability |
|
CVE-2026-21508
HIGH 7.0
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2026-21255
HIGH 8.8
Windows Hyper-V Security Feature Bypass Vulnerability |
|
CVE-2026-21253
HIGH 7.0
Mailslot File System Elevation of Privilege Vulnerability |
|
CVE-2026-21251
HIGH 7.8
Cluster Client Failover (CCF) Elevation of Privilege Vulnerability |
|
CVE-2026-21250
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21249
HIGH 3.3
Windows NTLM Spoofing Vulnerability |
|
CVE-2026-21248
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21247
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21246
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2026-21245
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21244
HIGH 7.3
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21243
HIGH 7.5
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2026-21242
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21241
HIGH 7.0
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21240
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21239
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21238
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21237
HIGH 7.0
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21236
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21235
HIGH 7.3
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2026-21234
HIGH 7.0
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2026-21232
HIGH 7.8
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21231
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21222
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-20846
HIGH 7.5
GDI+ Denial of Service Vulnerability |
|
CVE-2023-2804
HIGH 6.5
Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo |
|
CVE-2025-46316
MEDIUM 4.3
Réseau
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. Processing a… |
|
CVE-2025-46306
MEDIUM 5.5
Local
The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing a maliciously crafte… |
|
CVE-2026-0818
MEDIUM 4.3
Réseau 1 apps
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled… |
|
CVE-2025-11002
HIGH 7.8
Local 1 apps
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… |
|
CVE-2025-12781
MEDIUM 5.3
Réseau 1 apps
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepte… |
|
CVE-2025-43508
MEDIUM 5.5
Local
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data. |
|
CVE-2025-31186
LOW 3.3
Local 1 apps
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences. |
|
CVE-2025-24090
LOW 3.3
Local
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's insta… |
|
CVE-2025-24089
MEDIUM 5.3
Réseau
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's insta… |
|
CVE-2024-54556
LOW 2.4
Physique
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. A user may be able to view restricted content from… |
|
CVE-2024-44238
HIGH 7.8
Local
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be able to corrupt coproce… |
|
CVE-2024-44210
LOW 3.3
Local
This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data. |
|
CVE-2026-21265
MEDIUM 6.4
Local
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affect… |
|
CVE-2026-21221
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authoriz… |
|
CVE-2026-20962
MEDIUM 4.4
Local
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. |
|
CVE-2026-20941
HIGH 7.8
Local
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. |