Vulnérabilités
Vulnérabilités des apps suivies
26 374 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 26 374
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-10-06
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-68839
CRITICAL 9.8
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-68838
HIGH 8.0
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68837
HIGH 7.0
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68835
HIGH 7.1
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68834
HIGH 8.0
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68833
MEDIUM 6.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack. |
|
CVE-2026-68832
HIGH 7.8
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68831
MEDIUM 5.5
Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-68830
MEDIUM 5.5
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose … |
|
CVE-2026-68828
HIGH 8.8
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-68827
HIGH 8.0
Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-68825
HIGH 7.0
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-68824
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an autho… |
|
CVE-2026-62813
HIGH 7.5
Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network. |
|
CVE-2026-62810
HIGH 7.8
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62801
MEDIUM 6.5
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security featu… |
|
CVE-2026-62762
MEDIUM 6.5
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. |
|
CVE-2026-62759
HIGH 7.5
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network. |
|
CVE-2026-62744
HIGH 8.8
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-62706
HIGH 8.8
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-62697
HIGH 7.8
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-62694
HIGH 7.0
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56198
HIGH 7.8
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56177
HIGH 7.8
Use after free in Windows Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56172
HIGH 7.8
Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-50349
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz… |
|
CVE-2026-7477
HIGH 7.8
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows… |
|
CVE-2026-7476
HIGH 7.8
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows… |
|
CVE-2026-5729
HIGH 7.8
Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user proces… |
|
CVE-2026-12387
MEDIUM 5.1
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows… |
|
CVE-2026-12285
MEDIUM 4.0
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows… |
|
CVE-2026-85877
HIGH · éditeur
Windows Print Spooler Remote Code Execution Vulnerability |
|
CVE-2026-83991
HIGH · éditeur
Windows Cloud Files Mini Filter Driver Tampering Vulnerability |
|
CVE-2026-83986
HIGH · éditeur
Windows Biometric Service Elevation of Privilege Vulnerability |
|
CVE-2026-83975
HIGH · éditeur
Windows Biometric Service Elevation of Privilege Vulnerability |
|
CVE-2026-81963
Windows Update Stack Elevation of Privilege Vulnerability |
|
CVE-2026-78447
HIGH · éditeur
Windows Biometric Service Elevation of Privilege Vulnerability |
|
CVE-2026-85053
Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a… |
|
CVE-2026-85052
Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory … |
|
CVE-2026-85051
Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML… |
|
CVE-2026-85050
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via … |
|
CVE-2026-85049
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. … |
|
CVE-2026-85048
Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary c… |
|
CVE-2026-85047
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary… |
|
CVE-2026-85046
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C… |
|
CVE-2026-85045
Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C… |
|
CVE-2026-85044
Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web … |
|
CVE-2026-85043
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffi… |
|
CVE-2026-85042
Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML p… |
|
CVE-2026-84359
Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data v… |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.