Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 758 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 758
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-09-28

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 758 entrées
CVE
CVE-2025-9479
MEDIUM 4.3

Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch…

CVE-2025-13107
MEDIUM 4.3

Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (…

CVE-2025-13102
MEDIUM 4.3

Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofing via a craft…

CVE-2025-13097
MEDIUM 5.4

Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafte…

CVE-2024-9126
HIGH 7.5

Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

CVE-2024-7021
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome on Windows prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML…

CVE-2024-7017
HIGH 7.5

Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a craft…

CVE-2024-13983
MEDIUM 6.3

Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Ch…

CVE-2024-13178
MEDIUM 4.3

Inappropriate implementation in Fullscreen in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (C…

CVE-2024-11920
MEDIUM 4.3

Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a craf…

CVE-2024-11919
MEDIUM 4.3

Inappropriate implementation in Intents in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML …

CVE-2025-52331
MEDIUM 6.1

Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the …

CVE-2025-13042
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

CVE-2025-43205
MEDIUM 4.0

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, …

CVE-2025-62203
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-62202
HIGH 7.1

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2025-62201
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-62200
HIGH 7.8

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-62199
HIGH 7.8

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-60727
HIGH 7.8

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-60726
HIGH 7.1

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2025-60724
CRITICAL · éditeur

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2025-60722
MEDIUM 6.5

Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over…

CVE-2025-59240
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2025-65018
HIGH · éditeur

LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`

CVE-2025-64720
HIGH · éditeur

LIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication

CVE-2025-62452
HIGH · éditeur

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-62219
HIGH · éditeur

Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability

CVE-2025-62218
HIGH · éditeur

Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability

CVE-2025-62217
HIGH · éditeur

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-62215
HIGH · éditeur KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-62213
HIGH · éditeur

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-62209
HIGH · éditeur

Windows License Manager Information Disclosure Vulnerability

CVE-2025-62208
HIGH · éditeur

Windows License Manager Information Disclosure Vulnerability

CVE-2025-60723
HIGH · éditeur

DirectX Graphics Kernel Denial of Service Vulnerability

CVE-2025-60721
HIGH · éditeur

Windows Administrator Protection Elevation of Privilege Vulnerability

CVE-2025-60720
HIGH · éditeur

Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability

CVE-2025-60719
HIGH · éditeur

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-60718
HIGH · éditeur

Windows Administrator Protection Elevation of Privilege Vulnerability

CVE-2025-60717
HIGH · éditeur

Windows Broadcast DVR User Service Elevation of Privilege Vulnerability

CVE-2025-60716
CRITICAL · éditeur

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-60715
HIGH · éditeur

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-60714
HIGH · éditeur

Windows OLE Remote Code Execution Vulnerability

CVE-2025-60713
HIGH · éditeur

Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability

CVE-2025-60710
HIGH · éditeur KEV

Host Process for Windows Tasks Elevation of Privilege Vulnerability

CVE-2025-60709
HIGH · éditeur

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-60708
HIGH · éditeur

Storvsp.sys Driver Denial of Service Vulnerability

CVE-2025-60707
HIGH · éditeur

Multimedia Class Scheduler Service (MMCSS) Driver Elevation of Privilege Vulnerability

CVE-2025-60706
HIGH · éditeur

Windows Hyper-V Information Disclosure Vulnerability

CVE-2025-60705
HIGH · éditeur

Windows Client-Side Caching Elevation of Privilege Vulnerability

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa