Vulnérabilités
Vulnérabilités des apps suivies
25 753 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 372 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 753
- Activement exploitées
- 372
- Fenêtre de publication
- 1997-01-01 → 2026-09-17
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-8525
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted H… |
|
CVE-2026-8524
Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTM… |
|
CVE-2026-8523
Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a san… |
|
CVE-2026-8522
Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chrom… |
|
CVE-2026-8521
Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chrom… |
|
CVE-2026-8520
Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium … |
|
CVE-2026-8519
Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted … |
|
CVE-2026-8518
Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. … |
|
CVE-2026-8517
Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gest… |
|
CVE-2026-8516
Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in… |
|
CVE-2026-8515
Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially … |
|
CVE-2026-8514
Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a san… |
|
CVE-2026-8513
Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially p… |
|
CVE-2026-8512
Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to poten… |
|
CVE-2026-8511
Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chrom… |
|
CVE-2026-8510
Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an o… |
|
CVE-2026-8509
Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML … |
|
CVE-2026-41615
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-42893
HIGH 7.4
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a… |
|
CVE-2026-42832
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. |
|
CVE-2026-42831
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-41102
HIGH 7.1
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. |
|
CVE-2026-41101
HIGH 7.1
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. |
|
CVE-2026-41088
HIGH 7.8
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… |
|
CVE-2026-40421
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-40420
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-40418
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-40414
HIGH 7.4
Windows TCP/IP Denial of Service Vulnerability |
|
CVE-2026-40413
HIGH 7.4
Windows TCP/IP Denial of Service Vulnerability |
|
CVE-2026-40401
HIGH 7.1
Windows TCP/IP Denial of Service Vulnerability |
|
CVE-2026-40399
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileg… |
|
CVE-2026-40397
HIGH 7.8
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-40369
HIGH 7.8
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-40367
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-40366
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-40364
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-40363
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-40362
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-40361
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-40360
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-40359
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-40358
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-35440
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-35436
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-35429
MEDIUM 4.3
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a net… |
|
CVE-2026-35417
HIGH 7.8
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-35416
HIGH 7.0
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… |
|
CVE-2026-34345
HIGH 7.0
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… |
|
CVE-2026-34336
HIGH 7.8
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-34330
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p… |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.