Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

11 325 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2026-8960
HIGH 7.5 Réseau 1 apps

Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

CVE-2026-8959
HIGH 9.6 Réseau 1 apps

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbir…

CVE-2026-8958
HIGH 8.6 Réseau 1 apps

Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderb…

CVE-2026-8957
HIGH 8.8 Réseau 1 apps

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 14…

CVE-2026-8956
HIGH 9.8 Réseau 1 apps

Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

CVE-2026-8955
HIGH 8.8 Réseau 1 apps

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

CVE-2026-8954
HIGH 7.5 Réseau 1 apps

Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151,…

CVE-2026-8953
HIGH 9.6 Réseau 1 apps

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.…

CVE-2026-8952
HIGH 8.8 Réseau 1 apps

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

CVE-2026-8950
HIGH 9.3 Réseau 1 apps

Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird …

CVE-2026-8949
HIGH 7.5 Réseau 1 apps

Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

CVE-2026-8947
HIGH 7.3 Réseau 1 apps

Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, a…

CVE-2026-8946
HIGH 7.5 Réseau 1 apps

Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Th…

CVE-2025-54518
HIGH 7.0 Local

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a dif…

CVE-2026-42893
HIGH 7.4 Réseau 1 apps

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a…

CVE-2026-42832
HIGH 7.7 Local 2 apps

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

CVE-2026-41102
HIGH 7.1 Local 1 apps

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

CVE-2026-41101
HIGH 7.1 Local 1 apps

Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.

CVE-2026-41088
HIGH 7.8 Local

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-40414
HIGH 7.4 Réseau adjacent

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40413
HIGH 7.4 Réseau adjacent

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40401
HIGH 7.1 Local

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40399
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileg…

CVE-2026-40397
HIGH 7.8 Local

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-40369
HIGH 7.8 Local

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-35417
HIGH 7.8 Local

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVE-2026-35416
HIGH 7.0 Local

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-34345
HIGH 7.0 Local

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile…

CVE-2026-34336
HIGH 7.8 Local

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-34330
HIGH 7.8 Local

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p…

CVE-2026-33841
HIGH 7.8 Local

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-33840
HIGH 7.8 Local

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2025-46311
HIGH 7.5 Réseau

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.…

CVE-2025-43524
HIGH 8.8 Local

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app …

CVE-2026-42896
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2026-42825
HIGH 7.0

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-41097
HIGH 6.7

Secure Boot Security Feature Bypass Vulnerability

CVE-2026-41095
HIGH 7.8

Data Deduplication Elevation of Privilege Vulnerability

CVE-2026-40415
HIGH 8.1

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2026-40410
HIGH 7.0

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2026-40408
HIGH 7.8

Windows WAN ARP Driver Elevation of Privilege Vulnerability

CVE-2026-40407
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2026-40406
HIGH 7.5

Windows TCP/IP Information Disclosure Vulnerability

CVE-2026-40405
HIGH 7.5

Windows TCP/IP Denial of Service Vulnerability

CVE-2026-40398
HIGH 7.8

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-40382
HIGH 7.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-40380
HIGH 6.2

Windows Volume Manager Extension Driver Remote Code Execution Vulnerability

CVE-2026-40377
HIGH 7.8

Microsoft Cryptographic Services Elevation of Privilege Vulnerability

CVE-2026-35424
HIGH 7.5

Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

CVE-2026-35423
HIGH 5.4

Windows 11 Telnet Client Information Disclosure Vulnerability