Vulnérabilités
Vulnérabilités des apps suivies
15 629 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-24855
HIGH 7.8
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is… |
|
CVE-2025-24084
CRITICAL 8.4
Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability |
|
CVE-2025-24076
HIGH 7.3
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
|
CVE-2025-24072
HIGH 7.8
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability |
|
CVE-2025-24071
HIGH 6.5
Microsoft Windows File Explorer Spoofing Vulnerability |
|
CVE-2025-24067
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24066
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24064
CRITICAL 8.1
Windows Domain Name Service Remote Code Execution Vulnerability |
|
CVE-2025-24061
HIGH 7.8
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2025-24059
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24056
HIGH 8.8
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-24055
HIGH 4.3
Windows USB Video Class System Driver Information Disclosure Vulnerability |
|
CVE-2025-24054
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-24051
HIGH 8.8
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-24050
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-24048
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-24046
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24045
CRITICAL 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2025-24044
HIGH 7.8
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-24035
CRITICAL 8.1
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2025-21247
HIGH 4.3
MapUrlToZone Security Feature Bypass Vulnerability |
|
CVE-2025-21180
HIGH 7.8
Windows exFAT File System Remote Code Execution Vulnerability |
|
CVE-2024-9157
HIGH
Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading Vulnerability |
|
CVE-2024-55549
HIGH 7.8
xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue |
|
CVE-2025-26696
HIGH 7.0
Réseau 1 apps
Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown… |
|
CVE-2025-26695
MEDIUM 5.3
Local 1 apps
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested emai… |
|
CVE-2024-54560
MEDIUM 5.5
Local
A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A malicious app may be ab… |
|
CVE-2024-54558
LOW 2.8
Local
A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be abl… |
|
CVE-2024-54546
HIGH 7.5
Réseau
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause unexpected system termination or co… |
|
CVE-2024-54473
MEDIUM 5.5
Local
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An app may be able to access user-sensitive… |
|
CVE-2024-54469
MEDIUM 5.5
Local
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2.… |
|
CVE-2024-54467
MEDIUM 6.5
Réseau
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visi… |
|
CVE-2024-54463
MEDIUM 5.5
Local
This issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to access removable volumes without user conse… |
|
CVE-2024-44227
HIGH 7.5
Réseau
The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to cause unexpected sy… |
|
CVE-2024-44192
MEDIUM 5.5
Local
The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Proces… |
|
CVE-2024-44179
LOW 2.4
Physique
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoi… |
|
CVE-2025-1943
HIGH 8.2
Réseau 1 apps
Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-1942
CRITICAL 9.8
Réseau 1 apps
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability … |
|
CVE-2025-1938
MEDIUM 6.5
Réseau 1 apps
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption a… |
|
CVE-2025-1937
HIGH 7.5
Réseau 1 apps
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of… |
|
CVE-2025-1936
HIGH 7.3
Réseau 1 apps
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but… |
|
CVE-2025-1935
MEDIUM 4.3
Réseau 1 apps
A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR… |
|
CVE-2025-1934
MEDIUM 6.5
Réseau 1 apps
It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was no… |
|
CVE-2025-1933
HIGH 7.6
Réseau 1 apps
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a di… |
|
CVE-2025-1932
HIGH 8.1
Réseau 1 apps
An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This … |
|
CVE-2025-1931
HIGH 7.5
Réseau 1 apps
It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerabil… |
|
CVE-2025-1930
HIGH 8.8
Réseau 1 apps
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led t… |
|
CVE-2025-26417
HIGH
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22413
HIGH
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22412
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |