Vulnérabilités
Vulnérabilités des apps suivies
2 321 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2022-24480
MEDIUM 6.3
Physique 1 apps
Outlook for Android Elevation of Privilege Vulnerability |
|
CVE-2022-44698
MEDIUM 5.4
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-43363
MEDIUM 6.1
Réseau 2 apps
Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relati… |
|
CVE-2022-20468
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-20466
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-41099
MEDIUM 4.6
Physique
BitLocker Security Feature Bypass Vulnerability |
|
CVE-2022-41098
MEDIUM 5.5
Local
Windows GDI+ Information Disclosure Vulnerability |
|
CVE-2022-41097
MEDIUM 6.5
Réseau
Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability |
|
CVE-2022-41091
MEDIUM 5.4
KEV
Réseau
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2022-41090
MEDIUM 5.9
Réseau
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability |
|
CVE-2022-41086
MEDIUM 6.4
Local
Windows Group Policy Elevation of Privilege Vulnerability |
|
CVE-2022-41055
MEDIUM 5.5
Local
Windows Human Interface Device Information Disclosure Vulnerability |
|
CVE-2022-41049
MEDIUM 5.4
KEV
Réseau
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2022-38015
MEDIUM 6.5
Local
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2022-20454
MEDIUM 6.7
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-20415
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-20412
MEDIUM 6.7
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-20409
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-39758
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-20197
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-4189
MEDIUM 5.3
Réseau 1 apps
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the … |
|
CVE-2017-20052
MEDIUM 5.0
Réseau 1 apps
A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads… |
|
CVE-2022-32550
MEDIUM 4.8
Réseau 4 apps
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password servic… |
|
CVE-2022-25375
MEDIUM 5.5
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-25258
MEDIUM 4.6
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-29868
MEDIUM 5.5
Local 1 apps
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate… |
|
CVE-2021-39700
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2020-26558
MEDIUM 4.2
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2020-20096
MEDIUM 6.5
Réseau 2 apps
Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofin… |
|
CVE-2021-3733
MEDIUM 6.5
Réseau 1 apps
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects … |
|
CVE-2021-39689
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-23255
MEDIUM 5.9
Physique 1 apps
Microsoft OneDrive for Android Security Feature Bypass Vulnerability |
|
CVE-2013-3900
MEDIUM 5.5
KEV
WinVerifyTrust Signature Validation Vulnerability |
|
CVE-2021-43546
MEDIUM 4.3
Réseau 1 apps
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefo… |
|
CVE-2021-43545
MEDIUM 6.5
Réseau 1 apps
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0,… |
|
CVE-2021-43543
MEDIUM 6.1
Réseau 1 apps
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects… |
|
CVE-2021-43542
MEDIUM 6.5
Réseau 1 apps
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability aff… |
|
CVE-2021-43541
MEDIUM 6.5
Réseau 1 apps
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunder… |
|
CVE-2021-43538
MEDIUM 4.3
Réseau 1 apps
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock… |
|
CVE-2021-43536
MEDIUM 6.5
Réseau 1 apps
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < … |
|
CVE-2021-43528
MEDIUM 6.5
Réseau 1 apps
Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level… |
|
CVE-2021-38509
MEDIUM 4.3
Réseau 1 apps
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top a… |
|
CVE-2021-38508
MEDIUM 4.3
Réseau 1 apps
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could hav… |
|
CVE-2021-38507
MEDIUM 6.5
Réseau 1 apps
The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HT… |
|
CVE-2021-38506
MEDIUM 4.3
Réseau 1 apps
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on… |
|
CVE-2021-38505
MEDIUM 6.5
Réseau 1 apps
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it… |
|
CVE-2021-0969
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-0961
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-0958
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-38502
MEDIUM 5.9
Réseau 1 apps
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted mes… |