Vulnérabilités
Vulnérabilités des apps suivies
8 497 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-6763
MEDIUM 6.5
Réseau 1 apps
Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6762
MEDIUM 6.3
Réseau 1 apps
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thu… |
|
CVE-2026-6761
HIGH 8.8
Réseau 1 apps
Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6760
CRITICAL 9.8
Réseau 1 apps
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6759
HIGH 7.5
Réseau 1 apps
Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6758
HIGH 7.5
Réseau 1 apps
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6757
MEDIUM 6.3
Réseau 1 apps
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140… |
|
CVE-2026-6755
MEDIUM 6.5
Réseau 1 apps
Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6754
HIGH 7.5
Réseau 1 apps
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Th… |
|
CVE-2026-6753
HIGH 7.3
Réseau 1 apps
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6752
HIGH 7.3
Réseau 1 apps
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, an… |
|
CVE-2026-6751
HIGH 7.3
Réseau 1 apps
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbir… |
|
CVE-2026-6750
HIGH 8.8
Réseau 1 apps
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150… |
|
CVE-2026-6749
HIGH 7.5
Réseau 1 apps
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefo… |
|
CVE-2026-6748
CRITICAL 9.8
Réseau 1 apps
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbir… |
|
CVE-2026-6747
HIGH 7.5
Réseau 1 apps
Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6746
HIGH 7.5
Réseau 1 apps
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thu… |
|
CVE-2026-33829
MEDIUM 4.3
Réseau
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-33827
HIGH 8.1
Réseau
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o… |
|
CVE-2026-33826
HIGH 8.0
Réseau adjacent
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. |
|
CVE-2026-33824
CRITICAL 9.8
Réseau
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-33104
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p… |
|
CVE-2026-33101
HIGH 7.8
Local
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33100
HIGH 7.0
Local
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33099
HIGH 7.0
Local
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33098
HIGH 7.8
Local
Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33096
HIGH 7.5
Réseau
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-32225
HIGH 8.8
Réseau
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-32224
HIGH 7.0
Local
Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32223
MEDIUM 6.8
Physique
Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-32222
HIGH 7.8
Local
Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32221
HIGH 8.4
Local
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. |
|
CVE-2026-32220
MEDIUM 4.4
Local
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-32154
HIGH 7.8
Local
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32152
HIGH 7.8
Local
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32219
HIGH 7.0
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2026-32218
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-32217
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-32216
HIGH 5.5
Windows Redirected Drive Buffering System Denial of Service Vulnerability |
|
CVE-2026-32215
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-32214
HIGH 5.5
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
|
CVE-2026-32212
HIGH 5.5
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
|
CVE-2026-32202
HIGH 4.3
KEV
Windows Shell Spoofing Vulnerability |
|
CVE-2026-32195
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-32183
HIGH 7.8
Windows Snipping Tool Remote Code Execution Vulnerability |
|
CVE-2026-32181
HIGH 5.5
Connected User Experiences and Telemetry Service Denial of Service Vulnerability |
|
CVE-2026-32165
HIGH 7.8
Windows User Interface Core Elevation of Privilege Vulnerability |
|
CVE-2026-32164
HIGH 7.8
Windows User Interface Core Elevation of Privilege Vulnerability |
|
CVE-2026-32163
HIGH 7.8
Windows User Interface Core Elevation of Privilege Vulnerability |
|
CVE-2026-32162
HIGH 8.4
Windows COM Elevation of Privilege Vulnerability |