Vulnérabilités
Vulnérabilités des apps suivies
25 904 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 904
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-29
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-8364
MEDIUM 4.3
A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Androi… |
|
CVE-2025-55031
CRITICAL 9.8
Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have… |
|
CVE-2025-55030
MEDIUM 6.1
Firefox for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the content inline rather than downloading, pot… |
|
CVE-2025-55029
HIGH 7.5
Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. This vulnerability was fixed in Firefox … |
|
CVE-2025-55028
MEDIUM 6.5
Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service attacks. This … |
|
CVE-2025-54145
CRITICAL 9.1
The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that leveraged Firefox's open-text URL scheme. … |
|
CVE-2025-54144
MEDIUM 5.4
The URL scheme used by Firefox to facilitate searching of text queries could incorrectly allow attackers to open arbitrary website URLs or internal pages if a … |
|
CVE-2025-54143
CRITICAL 9.8
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vu… |
|
CVE-2025-8901
Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.… |
|
CVE-2025-8882
Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially… |
|
CVE-2025-8881
Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI ge… |
|
CVE-2025-8880
Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium sec… |
|
CVE-2025-8879
Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of g… |
|
CVE-2025-53783
HIGH 7.5
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. |
|
CVE-2025-53766
CRITICAL · éditeur
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. |
|
CVE-2025-53761
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
|
CVE-2025-53741
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-53739
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-53738
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2025-53737
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-53736
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
|
CVE-2025-53735
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-53733
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2025-53732
HIGH · éditeur
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-49755
MEDIUM 4.3
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2025-49736
MEDIUM 4.3
The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2025-38500
HIGH 7.8
In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md xfrm interface collect_md p… |
|
CVE-2025-55231
HIGH · éditeur
Windows Storage-based Management Service Remote Code Execution Vulnerability |
|
CVE-2025-55230
HIGH · éditeur
Windows MBT Transport Driver Elevation of Privilege Vulnerability |
|
CVE-2025-55229
HIGH · éditeur
Windows Certificate Spoofing Vulnerability |
|
CVE-2025-53789
HIGH · éditeur
Windows StateRepository API Server file Elevation of Privilege Vulnerability |
|
CVE-2025-53779
MEDIUM · éditeur
Windows Kerberos Elevation of Privilege Vulnerability |
|
CVE-2025-53778
CRITICAL · éditeur
Windows NTLM Elevation of Privilege Vulnerability |
|
CVE-2025-53726
HIGH · éditeur
Windows Push Notifications Apps Elevation of Privilege Vulnerability |
|
CVE-2025-53725
HIGH · éditeur
Windows Push Notifications Apps Elevation of Privilege Vulnerability |
|
CVE-2025-53724
HIGH · éditeur
Windows Push Notifications Apps Elevation of Privilege Vulnerability |
|
CVE-2025-53723
HIGH · éditeur
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-53722
HIGH · éditeur
Windows Remote Desktop Services Denial of Service Vulnerability |
|
CVE-2025-53721
HIGH · éditeur
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability |
|
CVE-2025-53720
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-53719
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-53718
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-53716
HIGH · éditeur
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
|
CVE-2025-53156
HIGH · éditeur
Windows Storage Port Driver Information Disclosure Vulnerability |
|
CVE-2025-53155
HIGH · éditeur
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-53154
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-53153
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-53152
HIGH · éditeur
Desktop Windows Manager Remote Code Execution Vulnerability |
|
CVE-2025-53151
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-53149
HIGH · éditeur
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.