Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

11 345 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2026-49784
HIGH 7.0 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to ele…

CVE-2026-49783
HIGH 7.8 Local

Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-49184
HIGH 8.4 Local

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-49183
HIGH 7.0 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevat…

CVE-2026-49181
HIGH 7.5 Réseau

Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-49178
HIGH 8.8 Réseau

Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

CVE-2026-49176
HIGH 7.8 Local

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

CVE-2026-49175
HIGH 7.8 Local

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-49173
HIGH 7.8 Local

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-49171
HIGH 7.5 Local

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

CVE-2026-49170
HIGH 7.8 Local

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

CVE-2026-49169
HIGH 8.0 Réseau

Use after free in DNS Server allows an authorized attacker to execute code over a network.

CVE-2026-49166
HIGH 7.8 Local

Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.

CVE-2026-49165
HIGH 7.1 Local

Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.

CVE-2026-49164
HIGH 8.1 Réseau

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

CVE-2026-49162
HIGH 7.0 Local

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-48572
HIGH 7.0 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate p…

CVE-2026-48571
HIGH 7.0 Local

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-48564
HIGH 8.8 Réseau

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

CVE-2026-44800
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev…

CVE-2026-42982
HIGH 7.8 Local

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-42975
HIGH 8.0 Réseau adjacent

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

CVE-2026-42900
HIGH 8.1 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate pri…

CVE-2026-40400
HIGH 8.0 Réseau

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

CVE-2026-40378
HIGH 7.5 Réseau

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over …

CVE-2026-15308
HIGH 7.5 Réseau 1 apps

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontr…

CVE-2026-43735
HIGH 8.1 Réseau

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6,…

CVE-2026-43731
HIGH 8.8 Réseau

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t…

CVE-2026-43725
HIGH 7.1 Réseau

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visi…

CVE-2026-43724
HIGH 7.8 Local

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS…

CVE-2026-43715
HIGH 8.8 Réseau

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, t…

CVE-2026-43705
HIGH 8.8 Réseau

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, v…

CVE-2026-43701
HIGH 7.1 Réseau

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6,…

CVE-2026-12328
HIGH 8.1 Réseau 1 apps

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed eviden…

CVE-2026-12327
HIGH 8.1 Réseau 1 apps

Memory safety bugs present in Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corrupt…

CVE-2026-12326
HIGH 8.1 Réseau 1 apps

Memory safety bugs present in Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2026-12324
HIGH 7.3 Réseau 1 apps

Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thu…

CVE-2026-12318
HIGH 7.3 Réseau 1 apps

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12317
HIGH 7.5 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

CVE-2026-12314
HIGH 7.5 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12312
HIGH 7.5 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12310
HIGH 7.5 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12305
HIGH 7.5 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

CVE-2026-12292
HIGH 8.1 Réseau 1 apps

Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140…

CVE-2026-12291
HIGH 8.8 Réseau 1 apps

Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thu…

CVE-2026-12290
HIGH 8.1 Réseau 1 apps

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 1…

CVE-2026-12289
HIGH 8.8 Réseau 1 apps

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152…

CVE-2026-8863
HIGH 7.8 Local

Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the bo…

CVE-2026-49160
HIGH 7.5 Réseau

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

CVE-2026-48583
HIGH 7.8 Local

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.