Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 753 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 372 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 753
Activement exploitées
372
Fenêtre de publication
1997-01-01 → 2026-09-17

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 753 entrées
CVE
CVE-2026-6301
HIGH 8.8

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pag…

CVE-2026-6300
HIGH 8.8

Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (C…

CVE-2026-6299
HIGH 8.8

Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium sec…

CVE-2026-6298
MEDIUM 4.3

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory…

CVE-2026-6297
HIGH 8.3

Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape v…

CVE-2026-6296
CRITICAL 9.6

Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pag…

CVE-2026-33829
MEDIUM 4.3

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-33827
HIGH 8.1

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o…

CVE-2026-33826
HIGH 8.0

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

CVE-2026-33824
CRITICAL 9.8 KEV

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

CVE-2026-33822
MEDIUM 6.1

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-33115
HIGH 8.4

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-33114
HIGH 8.4

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-33104
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p…

CVE-2026-33101
HIGH 7.8

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-33100
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-33099
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-33098
HIGH 7.8

Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-33096
HIGH 7.5

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

CVE-2026-33095
HIGH 7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-32225
HIGH 8.8

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-32224
HIGH 7.0

Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

CVE-2026-32223
MEDIUM 6.8

Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.

CVE-2026-32222
HIGH 7.8

Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

CVE-2026-32221
HIGH 8.4

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

CVE-2026-32220
MEDIUM 4.4

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

CVE-2026-32202
MEDIUM 4.3 KEV

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-32200
HIGH 7.8

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2026-32199
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-32198
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-32197
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-32189
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2026-32188
HIGH 7.1

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-32157
HIGH 8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-32154
HIGH 7.8

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-32153
HIGH 7.8

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

CVE-2026-32152
HIGH 7.8

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-26174
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to e…

CVE-2026-32219
HIGH · éditeur

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2026-32218
HIGH · éditeur

Windows Kernel Information Disclosure Vulnerability

CVE-2026-32217
HIGH · éditeur

Windows Kernel Information Disclosure Vulnerability

CVE-2026-32216
HIGH · éditeur

Windows Redirected Drive Buffering System Denial of Service Vulnerability

CVE-2026-32215
HIGH · éditeur

Windows Kernel Information Disclosure Vulnerability

CVE-2026-32214
HIGH · éditeur

Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability

CVE-2026-32212
HIGH · éditeur

Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability

CVE-2026-32195
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-32183
HIGH · éditeur

Windows Snipping Tool Remote Code Execution Vulnerability

CVE-2026-32181
HIGH · éditeur

Connected User Experiences and Telemetry Service Denial of Service Vulnerability

CVE-2026-32165
HIGH · éditeur

Windows User Interface Core Elevation of Privilege Vulnerability

CVE-2026-32164
HIGH · éditeur

Windows User Interface Core Elevation of Privilege Vulnerability

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa