Vulnérabilités
Vulnérabilités des apps suivies
25 758 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 758
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-28
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-9479
Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch… |
|
CVE-2025-13107
Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (… |
|
CVE-2025-13102
Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a craft… |
|
CVE-2025-13097
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafte… |
|
CVE-2024-9126
Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in specific UI gestures to … |
|
CVE-2024-7021
Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML… |
|
CVE-2024-7017
Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a craft… |
|
CVE-2024-13983
Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Ch… |
|
CVE-2024-13178
Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (C… |
|
CVE-2024-11920
Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a craf… |
|
CVE-2024-11919
Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML … |
|
CVE-2025-52331
MEDIUM 6.1
Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the … |
|
CVE-2025-13042
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML… |
|
CVE-2025-43205
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, … |
|
CVE-2025-62203
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62202
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2025-62201
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62200
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62199
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-60727
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-60726
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2025-60724
CRITICAL · éditeur
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2025-60722
MEDIUM 6.5
Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over… |
|
CVE-2025-59240
Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. |
|
CVE-2025-65018
LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read` |
|
CVE-2025-64720
LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication |
|
CVE-2025-62452
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-62219
HIGH · éditeur
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability |
|
CVE-2025-62218
HIGH · éditeur
Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability |
|
CVE-2025-62217
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-62215
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-62213
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-62209
HIGH · éditeur
Windows License Manager Information Disclosure Vulnerability |
|
CVE-2025-62208
HIGH · éditeur
Windows License Manager Information Disclosure Vulnerability |
|
CVE-2025-60723
HIGH · éditeur
DirectX Graphics Kernel Denial of Service Vulnerability |
|
CVE-2025-60721
HIGH · éditeur
Windows Administrator Protection Elevation of Privilege Vulnerability |
|
CVE-2025-60720
HIGH · éditeur
Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability |
|
CVE-2025-60719
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-60718
HIGH · éditeur
Windows Administrator Protection Elevation of Privilege Vulnerability |
|
CVE-2025-60717
HIGH · éditeur
Windows Broadcast DVR User Service Elevation of Privilege Vulnerability |
|
CVE-2025-60716
CRITICAL · éditeur
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-60715
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-60714
HIGH · éditeur
Windows OLE Remote Code Execution Vulnerability |
|
CVE-2025-60713
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability |
|
CVE-2025-60710
Host Process for Windows Tasks Elevation of Privilege Vulnerability |
|
CVE-2025-60709
HIGH · éditeur
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-60708
HIGH · éditeur
Storvsp.sys Driver Denial of Service Vulnerability |
|
CVE-2025-60707
HIGH · éditeur
Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability |
|
CVE-2025-60706
HIGH · éditeur
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2025-60705
HIGH · éditeur
Windows Client-Side Caching Elevation of Privilege Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.