Vulnérabilités
Vulnérabilités des apps suivies
15 629 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-8039
HIGH 8.1
Réseau 1 apps
In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability was fixed in Firefox 141, Firefox ESR 1… |
|
CVE-2025-8038
CRITICAL 9.8
Réseau 1 apps
Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141… |
|
CVE-2025-8037
CRITICAL 9.1
Réseau 1 apps
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie includ… |
|
CVE-2025-8036
HIGH 8.1
Réseau 1 apps
Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability was fixed in Fire… |
|
CVE-2025-8035
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of th… |
|
CVE-2025-8034
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunder… |
|
CVE-2025-8033
MEDIUM 6.5
Réseau 1 apps
The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in… |
|
CVE-2025-8032
HIGH 8.1
Réseau 1 apps
XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, … |
|
CVE-2025-8031
CRITICAL 9.8
Réseau 1 apps
The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability … |
|
CVE-2025-8030
HIGH 8.1
Réseau 1 apps
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in F… |
|
CVE-2025-8029
HIGH 8.1
Réseau 1 apps
Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 14… |
|
CVE-2025-8028
CRITICAL 9.8
Réseau 1 apps
On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect compu… |
|
CVE-2025-8027
MEDIUM 6.5
Réseau 1 apps
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulner… |
|
CVE-2025-38352
HIGH 7.8
KEV
Local
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If… |
|
CVE-2025-38349
HIGH 7.8
Local
In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still holding the ep mutex Jann Horn points … |
|
CVE-2025-53817
HIGH 7.5
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to version 25.0.0, a null pointer dereference … |
|
CVE-2025-53816
HIGH 7.5
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to memory corruption and denial of service … |
|
CVE-2025-6558
HIGH 8.8
KEV
Réseau
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox… |
|
CVE-2025-6965
HIGH 7.7
Réseau
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead… |
|
CVE-2025-49464
MEDIUM 6.5
Réseau 1 apps
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access. |
|
CVE-2025-49463
MEDIUM 6.5
Réseau 1 apps
Insufficient control flow management in certain Zoom Clients for iOS before version 6.4.5 may allow an unauthenticated user to conduct a disclosure of informat… |
|
CVE-2025-49462
LOW 3.5
Réseau 4 apps
Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access. |
|
CVE-2025-46789
MEDIUM 6.5
Réseau 1 apps
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access. |
|
CVE-2025-7425
HIGH 7.8
Local
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as… |
|
CVE-2025-7424
HIGH 7.5
Réseau
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML t… |
|
CVE-2025-48384
HIGH 8.0
KEV
Réseau 2 apps
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to int… |
|
CVE-2025-49731
LOW 3.1
Réseau 2 apps
Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network. |
|
CVE-2025-49702
CRITICAL 7.8
Local 1 apps
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-49697
CRITICAL 8.4
Local 1 apps
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-49696
CRITICAL 8.4
Local 1 apps
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-49695
CRITICAL 8.4
Local 1 apps
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-38236
HIGH 7.8
Local
In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't leave consecutive consumed OOB skbs. Jann Horn reported a use-after-free i… |
|
CVE-2025-49760
MEDIUM 3.5
Windows Storage Spoofing Vulnerability |
|
CVE-2025-49753
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-49744
HIGH 7.0
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-49742
HIGH 7.8
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2025-49740
HIGH 8.8
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2025-49735
CRITICAL 8.1
Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability |
|
CVE-2025-49733
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2025-49732
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-49730
HIGH 7.8
Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability |
|
CVE-2025-49729
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-49727
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2025-49726
HIGH 7.8
Windows Notification Elevation of Privilege Vulnerability |
|
CVE-2025-49725
HIGH 7.8
Windows Notification Elevation of Privilege Vulnerability |
|
CVE-2025-49724
HIGH 8.8
Windows Connected Devices Platform Service Remote Code Execution Vulnerability |
|
CVE-2025-49723
HIGH 8.8
Windows StateRepository API Server file Tampering Vulnerability |
|
CVE-2025-49722
HIGH 5.7
Windows Print Spooler Denial of Service Vulnerability |
|
CVE-2025-49721
HIGH 7.8
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-49716
HIGH 7.5
Windows Netlogon Denial of Service Vulnerability |