Vulnérabilités
Vulnérabilités des apps suivies
25 904 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 904
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-29
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-55679
HIGH · éditeur
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2025-55678
HIGH · éditeur
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-55677
HIGH · éditeur
Windows Device Association Broker Service Elevation of Privilege Vulnerability |
|
CVE-2025-55676
HIGH · éditeur
Windows USB Video Class System Driver Information Disclosure Vulnerability |
|
CVE-2025-55340
HIGH · éditeur
Windows Remote Desktop Protocol Security Feature Bypass |
|
CVE-2025-55339
HIGH · éditeur
Windows Network Driver Interface Specification (NDIS) Driver Elevation of Privilege Vulnerability |
|
CVE-2025-55338
HIGH · éditeur
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55337
HIGH · éditeur
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55336
HIGH · éditeur
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability |
|
CVE-2025-55335
HIGH · éditeur
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2025-55334
HIGH · éditeur
Windows Kernel Security Feature Bypass Vulnerability |
|
CVE-2025-55333
HIGH · éditeur
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55332
HIGH · éditeur
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55331
HIGH · éditeur
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability |
|
CVE-2025-55330
HIGH · éditeur
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-55328
HIGH · éditeur
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-55326
HIGH · éditeur
Windows Connected Devices Platform Service (Cdpsvc) Remote Code Execution Vulnerability |
|
CVE-2025-55325
HIGH · éditeur
Windows Storage Management Provider Information Disclosure Vulnerability |
|
CVE-2025-53768
HIGH · éditeur
Xbox IStorageService Elevation of Privilege Vulnerability |
|
CVE-2025-53717
HIGH · éditeur
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability |
|
CVE-2025-53150
HIGH · éditeur
Windows Digital Media Elevation of Privilege Vulnerability |
|
CVE-2025-53139
HIGH · éditeur
Windows Hello Security Feature Bypass Vulnerability |
|
CVE-2025-50175
HIGH · éditeur
Windows Digital Media Elevation of Privilege Vulnerability |
|
CVE-2025-50174
HIGH · éditeur
Windows Device Association Broker Service Elevation of Privilege Vulnerability |
|
CVE-2025-50152
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-49708
CRITICAL · éditeur
Microsoft Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-48813
HIGH · éditeur
Virtual Secure Mode Spoofing Vulnerability |
|
CVE-2025-48004
HIGH · éditeur
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-47979
HIGH · éditeur
Microsoft Failover Cluster Information Disclosure Vulnerability |
|
CVE-2025-47827
MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11 |
|
CVE-2025-25004
HIGH · éditeur
PowerShell Elevation of Privilege Vulnerability |
|
CVE-2025-24990
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24052
HIGH · éditeur
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-43296
MEDIUM 5.5
A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks. |
|
CVE-2025-10859
MEDIUM 4.0
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing information from private tabs to escape Inc… |
|
CVE-2025-43400
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.1 and iPadOS 18.7.1, iOS 26.0.1 and iPadOS 26.0.1, ma… |
|
CVE-2025-10892
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro… |
|
CVE-2025-10891
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro… |
|
CVE-2025-10890
Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (C… |
|
CVE-2025-10585
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2025-10502
Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network t… |
|
CVE-2025-10501
Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch… |
|
CVE-2025-10500
Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro… |
|
CVE-2025-21488
HIGH 8.2
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set. |
|
CVE-2025-21487
HIGH 8.2
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. |
|
CVE-2025-21484
HIGH 8.2
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. |
|
CVE-2025-21482
HIGH 7.1
Cryptographic issue while performing RSA PKCS padding decoding. |
|
CVE-2025-47967
MEDIUM 4.7
Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2025-10537
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2025-10536
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140… |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.