Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

11 306 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2025-53768
HIGH 7.8

Xbox IStorageService Elevation of Privilege Vulnerability

CVE-2025-53717
HIGH 7.0

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

CVE-2025-53150
HIGH 7.8

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-53139
HIGH 7.7

Windows Hello Security Feature Bypass Vulnerability

CVE-2025-50175
HIGH 7.8

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-50174
HIGH 7.0

Windows Device Association Broker Service Elevation of Privilege Vulnerability

CVE-2025-50152
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-48813
HIGH 6.3

Virtual Secure Mode Spoofing Vulnerability

CVE-2025-48004
HIGH 7.4

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-47979
HIGH 5.5

Microsoft Failover Cluster Information Disclosure Vulnerability

CVE-2025-47827
HIGH 4.6 KEV

MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11

CVE-2025-25004
HIGH 7.3

PowerShell Elevation of Privilege Vulnerability

CVE-2025-24990
HIGH 7.8 KEV

Windows Agere Modem Driver Elevation of Privilege Vulnerability

CVE-2025-24052
HIGH 7.8

Windows Agere Modem Driver Elevation of Privilege Vulnerability

CVE-2025-10537
HIGH 8.8 Réseau 1 apps

Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruptio…

CVE-2025-10534
HIGH 8.1 Réseau 1 apps

Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

CVE-2025-10533
HIGH 8.8 Réseau 1 apps

Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140…

CVE-2025-10528
HIGH 7.3 Réseau 1 apps

Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, …

CVE-2025-10527
HIGH 7.1 Réseau 1 apps

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and …

CVE-2025-43372
HIGH 7.8 Local

The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Tahoe 26, tvOS 26, visionOS 26,…

CVE-2025-43371
HIGH 8.2 Local 1 apps

This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox.

CVE-2025-43358
HIGH 8.8 Local

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15…

CVE-2025-43341
HIGH 7.8 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to gain root privi…

CVE-2025-43340
HIGH 7.8 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to break out of its sandbox.

CVE-2025-43333
HIGH 7.8 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to gain root privileges.

CVE-2025-43330
HIGH 8.2 Local

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to break out of its san…

CVE-2025-43329
HIGH 8.8 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, watchOS 26. An app may be…

CVE-2025-43316
HIGH 7.8 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26, visionOS 26. A malicious app may be able to gain root pr…

CVE-2025-43304
HIGH 7.0 Local

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able t…

CVE-2025-43298
HIGH 7.8 Local

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, m…

CVE-2025-43287
HIGH 7.1 Local

The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26. Processing a maliciously crafted image may corrupt process memory.

CVE-2025-43286
HIGH 7.8 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be abl…

CVE-2025-43263
HIGH 7.1 Local 1 apps

The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox.

CVE-2025-43204
HIGH 7.8 Local

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to break out of its sandbox.

CVE-2025-31271
HIGH 7.5 Réseau

This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime calls can appear or be accepted on a locke…

CVE-2025-24088
HIGH 7.5 Réseau

The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to override MDM-enforced settings from profiles.

CVE-2025-9086
HIGH 7.5 Réseau

1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostnam…

CVE-2025-59220
HIGH 7.0

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-59216
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-59215
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-55234
HIGH 8.8

Windows SMB Elevation of Privilege Vulnerability

CVE-2025-55225
HIGH 6.5

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

CVE-2025-55223
HIGH 7.0

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-54919
HIGH 7.5

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2025-54917
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-54916
HIGH 7.8

Windows NTFS Remote Code Execution Vulnerability

CVE-2025-54915
HIGH 6.7

Windows Defender Firewall Service Elevation of Privilege Vulnerability

CVE-2025-54913
HIGH 7.8

Windows UI XAML Maps MapControlSettings Elevation of Privilege Vulnerability

CVE-2025-54912
HIGH 7.8

Windows BitLocker Elevation of Privilege Vulnerability

CVE-2025-54911
HIGH 7.3

Windows BitLocker Elevation of Privilege Vulnerability