Vulnérabilités
Vulnérabilités des apps suivies
2 297 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-46306
MEDIUM 5.5
Local
The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing a maliciously crafte… |
|
CVE-2026-0818
MEDIUM 4.3
Réseau 1 apps
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled… |
|
CVE-2025-12781
MEDIUM 5.3
Réseau 1 apps
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepte… |
|
CVE-2025-43508
MEDIUM 5.5
Local
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data. |
|
CVE-2025-24089
MEDIUM 5.3
Réseau
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's insta… |
|
CVE-2026-21265
MEDIUM 6.4
Local
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affect… |
|
CVE-2026-20962
MEDIUM 4.4
Local
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. |
|
CVE-2026-20939
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20937
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20936
MEDIUM 4.3
Physique
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. |
|
CVE-2026-20935
MEDIUM 6.2
Local
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-20932
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20927
MEDIUM 5.3
Réseau
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service… |
|
CVE-2026-20925
MEDIUM 6.5
Réseau
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-20876
MEDIUM 6.7
Local
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20872
MEDIUM 6.5
Réseau
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-20862
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally. |
|
CVE-2026-20851
MEDIUM 6.2
Local
Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-20847
MEDIUM 6.5
Réseau
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network. |
|
CVE-2026-20839
MEDIUM 5.5
Local
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-20838
MEDIUM 5.5
Local
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-20835
MEDIUM 5.5
Local
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. |
|
CVE-2026-20834
MEDIUM 4.6
Physique
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. |
|
CVE-2026-20829
MEDIUM 5.5
Local
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. |
|
CVE-2026-20828
MEDIUM 4.6
Physique
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-20827
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose inform… |
|
CVE-2026-20825
MEDIUM 4.4
Local
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. |
|
CVE-2026-20824
MEDIUM 5.5
Local
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2026-20823
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20821
MEDIUM 6.2
Local
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-20819
MEDIUM 5.5
Local
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. |
|
CVE-2026-20812
MEDIUM 6.5
Réseau
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. |
|
CVE-2026-20805
MEDIUM 5.5
KEV
Local
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. |
|
CVE-2026-0890
MEDIUM 5.4
Réseau 1 apps
Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunder… |
|
CVE-2026-0888
MEDIUM 5.3
Réseau 1 apps
Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. |
|
CVE-2026-0887
MEDIUM 4.3
Réseau 1 apps
Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Th… |
|
CVE-2026-0886
MEDIUM 5.3
Réseau 1 apps
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, a… |
|
CVE-2026-0885
MEDIUM 6.5
Réseau 1 apps
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0883
MEDIUM 5.3
Réseau 1 apps
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2025-46299
MEDIUM 4.3
Réseau
A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS… |
|
CVE-2025-46298
MEDIUM 6.5
Réseau
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2… |
|
CVE-2025-46297
MEDIUM 5.5
Local
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files within an… |
|
CVE-2025-46286
MEDIUM 4.3
Réseau
A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a backup may prevent passcode from being … |
|
CVE-2025-62224
MEDIUM 5.5
Réseau 1 apps
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. |
|
CVE-2025-46292
MEDIUM 5.5
Local
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able … |
|
CVE-2025-46288
MEDIUM 5.5
Local
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2.… |
|
CVE-2025-46283
MEDIUM 5.5
Local
A logic issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to access sensitive user… |
|
CVE-2025-46282
MEDIUM 5.5
Local
The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app may be able to access sensitive user d… |
|
CVE-2025-46278
MEDIUM 5.5
Local
The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected user data. |
|
CVE-2025-43541
MEDIUM 4.3
Réseau
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, … |