Vulnérabilités
Vulnérabilités des apps suivies
25 758 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 758
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-28
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-62464
HIGH · éditeur
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-62463
HIGH · éditeur
DirectX Graphics Kernel Denial of Service Vulnerability |
|
CVE-2025-62462
HIGH · éditeur
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-62461
HIGH · éditeur
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-62458
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2025-62457
HIGH · éditeur
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-62456
HIGH · éditeur
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
|
CVE-2025-62454
HIGH · éditeur
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-59517
HIGH · éditeur
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
|
CVE-2025-59516
HIGH · éditeur
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
|
CVE-2025-55233
HIGH · éditeur
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2025-54100
HIGH · éditeur
PowerShell Remote Code Execution Vulnerability |
|
CVE-2025-48615
HIGH 7.8
In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local escalatio… |
|
CVE-2025-48612
HIGH 7.8
In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's default NFC payment setting due to improper … |
|
CVE-2025-48600
MEDIUM 5.5
In multiple files, there is a possible way to reveal information across users due to a missing permission check. This could lead to local information disclosur… |
|
CVE-2025-48566
HIGH 7.8
In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional exec… |
|
CVE-2025-48565
HIGH 7.8
In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code. This could lead to local escalation … |
|
CVE-2025-48564
HIGH 7.0
In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escalation of privilege with no additional ex… |
|
CVE-2025-58098
HIGH 8.3
Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd… |
|
CVE-2025-65082
MEDIUM 6.5
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuratio… |
|
CVE-2025-59775
HIGH 7.5
Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows with AllowEncodedSlashes On and MergeSlashes Off allows to potentially … |
|
CVE-2025-40266
HIGH 8.2
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset to prevent … |
|
CVE-2025-40214
HIGH 7.8
In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC c… |
|
CVE-2025-13992
Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a cra… |
|
CVE-2025-12084
When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Avail… |
|
CVE-2025-13721
Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security… |
|
CVE-2025-13720
Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corru… |
|
CVE-2025-13640
Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass authentication via physical access to the … |
|
CVE-2025-13639
Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML pag… |
|
CVE-2025-13638
Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… |
|
CVE-2025-13637
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestu… |
|
CVE-2025-13636
Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gest… |
|
CVE-2025-13635
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chr… |
|
CVE-2025-13634
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the web via a crafted H… |
|
CVE-2025-13633
Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially… |
|
CVE-2025-13632
Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a user to install a malicious extension to p… |
|
CVE-2025-13631
Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a c… |
|
CVE-2025-13630
Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… |
|
CVE-2025-20755
MEDIUM 5.3
In Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue… |
|
CVE-2025-13837
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues |
|
CVE-2025-13836
When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server… |
|
CVE-2025-3012
HIGH 7.5
In dpc modem, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privil… |
|
CVE-2025-8045
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-6573
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-6349
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-61619
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-61618
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-61617
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-61610
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-61609
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.