Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

26 374 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
26 374
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-10-06

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

26 374 entrées
CVE
CVE-2026-68839
CRITICAL 9.8

Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.

CVE-2026-68838
HIGH 8.0

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-68837
HIGH 7.0

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

CVE-2026-68835
HIGH 7.1

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.

CVE-2026-68834
HIGH 8.0

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.

CVE-2026-68833
MEDIUM 6.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-68832
HIGH 7.8

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-68831
MEDIUM 5.5

Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

CVE-2026-68830
MEDIUM 5.5

Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose …

CVE-2026-68828
HIGH 8.8

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-68827
HIGH 8.0

Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.

CVE-2026-68825
HIGH 7.0

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-68824
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an autho…

CVE-2026-62813
HIGH 7.5

Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.

CVE-2026-62810
HIGH 7.8

Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

CVE-2026-62801
MEDIUM 6.5

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security featu…

CVE-2026-62762
MEDIUM 6.5

Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

CVE-2026-62759
HIGH 7.5

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

CVE-2026-62744
HIGH 8.8

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-62706
HIGH 8.8

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

CVE-2026-62697
HIGH 7.8

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-62694
HIGH 7.0

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-56198
HIGH 7.8

Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.

CVE-2026-56177
HIGH 7.8

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

CVE-2026-56172
HIGH 7.8

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50349
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz…

CVE-2026-7477
HIGH 7.8

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows…

CVE-2026-7476
HIGH 7.8

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows…

CVE-2026-5729
HIGH 7.8

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user proces…

CVE-2026-12387
MEDIUM 5.1

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows…

CVE-2026-12285
MEDIUM 4.0

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows…

CVE-2026-85877
HIGH · éditeur

Windows Print Spooler Remote Code Execution Vulnerability

CVE-2026-83991
HIGH · éditeur

Windows Cloud Files Mini Filter Driver Tampering Vulnerability

CVE-2026-83986
HIGH · éditeur

Windows Biometric Service Elevation of Privilege Vulnerability

CVE-2026-83975
HIGH · éditeur

Windows Biometric Service Elevation of Privilege Vulnerability

CVE-2026-81963
HIGH · éditeur KEV

Windows Update Stack Elevation of Privilege Vulnerability

CVE-2026-78447
HIGH · éditeur

Windows Biometric Service Elevation of Privilege Vulnerability

CVE-2026-85053
HIGH 8.8

Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a…

CVE-2026-85052
LOW 3.1

Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory …

CVE-2026-85051
HIGH 8.8

Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML…

CVE-2026-85050
CRITICAL 9.6

Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via …

CVE-2026-85049
HIGH 8.8

Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. …

CVE-2026-85048
HIGH 8.3

Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary c…

CVE-2026-85047
CRITICAL 9.6

Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary…

CVE-2026-85046
HIGH 8.8 KEV

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C…

CVE-2026-85045
HIGH 7.5

Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C…

CVE-2026-85044
MEDIUM 6.5

Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web …

CVE-2026-85043
CRITICAL 9.1

Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffi…

CVE-2026-85042
CRITICAL 9.6

Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML p…

CVE-2026-84359
LOW 3.1

Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data v…

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa