Vulnérabilités
Vulnérabilités des apps suivies
25 758 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 758
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-28
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-21255
HIGH · éditeur
Windows Hyper-V Security Feature Bypass Vulnerability |
|
CVE-2026-21253
HIGH · éditeur
Mailslot File System Elevation of Privilege Vulnerability |
|
CVE-2026-21251
HIGH · éditeur
Cluster Client Failover (CCF) Elevation of Privilege Vulnerability |
|
CVE-2026-21250
HIGH · éditeur
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21249
HIGH · éditeur
Windows NTLM Spoofing Vulnerability |
|
CVE-2026-21248
HIGH · éditeur
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21247
HIGH · éditeur
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21246
HIGH · éditeur
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2026-21245
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21244
HIGH · éditeur
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2026-21243
HIGH · éditeur
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2026-21242
HIGH · éditeur
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21241
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21240
HIGH · éditeur
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21239
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21238
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21237
HIGH · éditeur
Windows Subsystem for Linux Elevation of Privilege Vulnerability |
|
CVE-2026-21236
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2026-21235
HIGH · éditeur
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2026-21234
HIGH · éditeur
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2026-21232
HIGH · éditeur
Windows HTTP.sys Elevation of Privilege Vulnerability |
|
CVE-2026-21231
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2026-21222
HIGH · éditeur
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2023-2804
HIGH · éditeur
Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo |
|
CVE-2026-1862
Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2026-1861
Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… |
|
CVE-2025-46316
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. Processing a… |
|
CVE-2025-46306
The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing a maliciously crafte… |
|
CVE-2026-0818
MEDIUM 4.3
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled… |
|
CVE-2026-1504
Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker to leak cross-origin data via a crafted… |
|
CVE-2026-21509
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-11002
HIGH 7.8
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… |
|
CVE-2025-12781
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepte… |
|
CVE-2026-0908
Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro… |
|
CVE-2026-0907
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium… |
|
CVE-2026-0906
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafte… |
|
CVE-2026-0905
Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain pote… |
|
CVE-2026-0904
Incorrect security UI in Digital Credentials in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform domain spoofing via a crafted HTML pa… |
|
CVE-2026-0903
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 144.0.7559.59 allowed a remote attacker to bypass dangerous file type protection… |
|
CVE-2026-0902
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML… |
|
CVE-2026-0901
Inappropriate implementation in Blink in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML pa… |
|
CVE-2026-0900
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTM… |
|
CVE-2026-0899
Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML… |
|
CVE-2025-43508
MEDIUM 5.5
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data. |
|
CVE-2025-31186
LOW 3.3
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences. |
|
CVE-2025-24090
LOW 3.3
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's insta… |
|
CVE-2025-24089
MEDIUM 5.3
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's insta… |
|
CVE-2024-54556
LOW 2.4
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. A user may be able to view restricted content from… |
|
CVE-2024-44238
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app may be able to corrupt coproce… |
|
CVE-2024-44210
LOW 3.3
This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data. |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.