Vulnérabilités
Vulnérabilités des apps suivies
25 758 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 758
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-28
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-64658
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privilege… |
|
CVE-2025-62564
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62563
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62562
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62561
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62560
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62559
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62558
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62557
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62556
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62555
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62554
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62553
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62455
HIGH 7.8
Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. |
|
CVE-2025-62221
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2025-14333
Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2025-14332
Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-14331
Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 14… |
|
CVE-2025-14330
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14… |
|
CVE-2025-14329
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. |
|
CVE-2025-14328
Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. |
|
CVE-2025-14327
Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7. |
|
CVE-2025-14326
Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146. |
|
CVE-2025-14325
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14… |
|
CVE-2025-14324
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146… |
|
CVE-2025-14323
Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, … |
|
CVE-2025-14322
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Fi… |
|
CVE-2025-14321
Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. |
|
CVE-2025-64680
HIGH · éditeur
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-64679
HIGH · éditeur
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-64678
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-64673
HIGH · éditeur
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
|
CVE-2025-64670
HIGH · éditeur
Windows DirectX Information Disclosure Vulnerability |
|
CVE-2025-62573
HIGH · éditeur
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-62572
HIGH · éditeur
Application Information Service Elevation of Privilege Vulnerability |
|
CVE-2025-62571
HIGH · éditeur
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2025-62570
HIGH · éditeur
Windows Camera Frame Server Monitor Information Disclosure Vulnerability |
|
CVE-2025-62569
HIGH · éditeur
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-62567
HIGH · éditeur
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2025-62565
HIGH · éditeur
Windows File Explorer Elevation of Privilege Vulnerability |
|
CVE-2025-62549
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-62474
HIGH · éditeur
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2025-62473
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-62472
HIGH · éditeur
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2025-62470
HIGH · éditeur
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-62469
HIGH · éditeur
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-62468
HIGH · éditeur
Windows Defender Firewall Service Information Disclosure Vulnerability |
|
CVE-2025-62467
HIGH · éditeur
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-62466
HIGH · éditeur
Windows Client-Side Caching Elevation of Privilege Vulnerability |
|
CVE-2025-62465
HIGH · éditeur
DirectX Graphics Kernel Denial of Service Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.