Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

15 602 CVE touchent une app ou un OS suivi (Élevé, toutes plateformes). 294 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
15 602
Activement exploitées
294
Fenêtre de publication
2004-07-27 → 2026-09-17

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

15 602 entrées Élevé Tout effacer
CVE
CVE-2026-16398
HIGH 7.5

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16396
HIGH 8.8

Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVE-2026-16391
HIGH 7.5

Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1…

CVE-2026-16386
HIGH 7.5

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16385
HIGH 7.5

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16384
HIGH 7.5

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16379
HIGH 8.8

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird…

CVE-2026-16378
HIGH 7.5

Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16376
HIGH 7.5

Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16374
HIGH 7.5

Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbir…

CVE-2026-16372
HIGH 8.8

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16371
HIGH 8.8

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, Thunderbird 140.13, Fi…

CVE-2026-16366
HIGH 8.8

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVE-2026-16365
HIGH 8.8

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153, Thunderbird 153, Firefox ESR 140.15, and Thunderbird 140.15.

CVE-2026-16362
HIGH 8.8

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVE-2026-16354
HIGH 7.5

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 15…

CVE-2026-15905
HIGH 7.8

Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium…

CVE-2026-15904
HIGH 8.8

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to p…

CVE-2026-15903
HIGH 8.8

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

CVE-2026-15902
HIGH 8.8

Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (…

CVE-2026-58598
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate p…

CVE-2026-15777
HIGH 7.5

Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to pote…

CVE-2026-15776
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

CVE-2026-15774
HIGH 8.3

Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a san…

CVE-2026-15772
HIGH 8.3

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially per…

CVE-2026-15769
HIGH 8.3

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had comprom…

CVE-2026-15767
HIGH 8.8

Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a c…

CVE-2026-15765
HIGH 7.5

Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentiall…

CVE-2026-15764
HIGH 7.5

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to p…

CVE-2026-58637
HIGH 7.0

Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58634
HIGH 7.8

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-58633
HIGH 7.8

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-58632
HIGH 7.8

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-58629
HIGH 7.0

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVE-2026-58628
HIGH 7.8

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to ele…

CVE-2026-58627
HIGH 7.5

Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-58626
HIGH 8.8

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

CVE-2026-58619
HIGH 7.0

Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58613
HIGH 7.8

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-58594
HIGH 8.8

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

CVE-2026-58544
HIGH 7.0

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

CVE-2026-58542
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-58541
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.

CVE-2026-58540
HIGH 7.8

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-58538
HIGH 7.8

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58537
HIGH 7.8

Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.

CVE-2026-58536
HIGH 7.8

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-58534
HIGH 8.8

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

CVE-2026-58532
HIGH 7.8

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-58531
HIGH 7.5

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges …

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa