Vulnérabilités
Vulnérabilités des apps suivies
25 758 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 372 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 758
- Activement exploitées
- 372
- Fenêtre de publication
- 1997-01-01 → 2026-09-28
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-3930
Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML p… |
|
CVE-2026-3929
Side-channel information leakage in ResourceTiming in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to leak cross-origin data via a crafted HT… |
|
CVE-2026-3928
Insufficient policy enforcement in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension… |
|
CVE-2026-3927
Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Ch… |
|
CVE-2026-3926
Out of bounds read in V8 in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chr… |
|
CVE-2026-3925
Incorrect security UI in LookalikeChecks in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML… |
|
CVE-2026-3924
use after free in WindowDialog in Google Chrome prior to 146.0.7680.71 allowed a remote attacker who had compromised the renderer process to potentially perfor… |
|
CVE-2026-3923
Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch… |
|
CVE-2026-3922
Use after free in MediaStream in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.… |
|
CVE-2026-3921
Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… |
|
CVE-2026-3920
Out of bounds memory access in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM… |
|
CVE-2026-3919
Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially e… |
|
CVE-2026-3918
Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
|
CVE-2026-3917
Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
|
CVE-2026-3916
Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p… |
|
CVE-2026-3915
Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page… |
|
CVE-2026-3914
Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch… |
|
CVE-2026-3913
Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.… |
|
CVE-2026-3784
curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. Th… |
|
CVE-2026-3783
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second ho… |
|
CVE-2026-26123
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-26134
HIGH · éditeur
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-26112
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-26110
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2026-26109
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-26108
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-26107
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2026-25180
HIGH · éditeur
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-24294
HIGH 7.8
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-24293
HIGH 7.8
Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-24289
HIGH 7.8
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-24285
HIGH · éditeur
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33636
HIGH · éditeur
LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64 |
|
CVE-2026-26132
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-26128
HIGH · éditeur
Windows SMB Server Elevation of Privilege Vulnerability |
|
CVE-2026-26111
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2026-25190
HIGH · éditeur
Windows GDI Remote Code Execution Vulnerability |
|
CVE-2026-25189
HIGH · éditeur
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2026-25188
HIGH · éditeur
Windows Telephony Service Elevation of Privilege Vulnerability |
|
CVE-2026-25187
HIGH · éditeur
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2026-25186
HIGH · éditeur
Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability |
|
CVE-2026-25185
HIGH · éditeur
Windows Shell Link Processing Spoofing Vulnerability |
|
CVE-2026-25181
HIGH · éditeur
GDI+ Information Disclosure Vulnerability |
|
CVE-2026-25179
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-25178
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-25177
HIGH · éditeur
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2026-25176
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-25175
HIGH · éditeur
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2026-25174
HIGH · éditeur
Windows Extensible File Allocation Table Elevation of Privilege Vulnerability |
|
CVE-2026-25173
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.