Vulnérabilités
Vulnérabilités des apps suivies
25 753 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 372 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 753
- Activement exploitées
- 372
- Fenêtre de publication
- 1997-01-01 → 2026-09-17
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-6301
Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pag… |
|
CVE-2026-6300
Use after free in CSS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (C… |
|
CVE-2026-6299
Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium sec… |
|
CVE-2026-6298
Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory… |
|
CVE-2026-6297
Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape v… |
|
CVE-2026-6296
Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pag… |
|
CVE-2026-33829
MEDIUM 4.3
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-33827
HIGH 8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o… |
|
CVE-2026-33826
HIGH 8.0
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. |
|
CVE-2026-33824
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-33822
MEDIUM 6.1
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-33115
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-33114
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-33104
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate p… |
|
CVE-2026-33101
HIGH 7.8
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33100
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33099
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33098
HIGH 7.8
Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33096
HIGH 7.5
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-33095
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2026-32225
HIGH 8.8
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-32224
HIGH 7.0
Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32223
MEDIUM 6.8
Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. |
|
CVE-2026-32222
HIGH 7.8
Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32221
HIGH 8.4
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. |
|
CVE-2026-32220
MEDIUM 4.4
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-32202
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-32200
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
|
CVE-2026-32199
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-32198
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-32197
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-32189
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-32188
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-32157
HIGH 8.8
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-32154
HIGH 7.8
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32153
HIGH 7.8
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32152
HIGH 7.8
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-26174
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to e… |
|
CVE-2026-32219
HIGH · éditeur
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2026-32218
HIGH · éditeur
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-32217
HIGH · éditeur
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-32216
HIGH · éditeur
Windows Redirected Drive Buffering System Denial of Service Vulnerability |
|
CVE-2026-32215
HIGH · éditeur
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2026-32214
HIGH · éditeur
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
|
CVE-2026-32212
HIGH · éditeur
Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability |
|
CVE-2026-32195
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-32183
HIGH · éditeur
Windows Snipping Tool Remote Code Execution Vulnerability |
|
CVE-2026-32181
HIGH · éditeur
Connected User Experiences and Telemetry Service Denial of Service Vulnerability |
|
CVE-2026-32165
HIGH · éditeur
Windows User Interface Core Elevation of Privilege Vulnerability |
|
CVE-2026-32164
HIGH · éditeur
Windows User Interface Core Elevation of Privilege Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.