Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 929 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 929
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-09-29

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 929 entrées
CVE
CVE-2025-47985
HIGH · éditeur

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2025-47984
HIGH · éditeur

Windows GDI Information Disclosure Vulnerability

CVE-2025-47982
HIGH · éditeur

Windows Storage VSP Driver Elevation of Privilege Vulnerability

CVE-2025-47981
CRITICAL · éditeur

SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability

CVE-2025-47980
CRITICAL · éditeur

Windows Imaging Component Information Disclosure Vulnerability

CVE-2025-47978
HIGH · éditeur

Windows Kerberos Denial of Service Vulnerability

CVE-2025-47976
HIGH · éditeur

Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability

CVE-2025-47975
HIGH · éditeur

Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability

CVE-2025-47973
HIGH · éditeur

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-47972
HIGH · éditeur

Windows Input Method Editor (IME) Elevation of Privilege Vulnerability

CVE-2025-47971
HIGH · éditeur

Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability

CVE-2025-47159
HIGH · éditeur

Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability

CVE-2025-33054
HIGH · éditeur

Remote Desktop Spoofing Vulnerability

CVE-2025-26636
HIGH · éditeur

Windows Kernel Information Disclosure Vulnerability

CVE-2024-36357
CRITICAL · éditeur

AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue

CVE-2024-36350
CRITICAL · éditeur

AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue

CVE-2025-6554
HIGH 8.1 KEV

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium secur…

CVE-2025-32462
LOW 2.8

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on …

CVE-2025-6557
MEDIUM 5.4

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specifi…

CVE-2025-6556
MEDIUM 5.4

Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTM…

CVE-2025-6555
MEDIUM 5.4

Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (…

CVE-2025-6436
HIGH 8.1

Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-6435
HIGH 8.1

If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file …

CVE-2025-6434
MEDIUM 4.3

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker…

CVE-2025-6433
CRITICAL 9.8

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would…

CVE-2025-6432
HIGH 8.6

When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not respondin…

CVE-2025-6430
MEDIUM 6.1

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<…

CVE-2025-6429
MEDIUM 6.5

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypas…

CVE-2025-6427
CRITICAL 9.1

An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connectio…

CVE-2025-6426
HIGH 8.8

The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of…

CVE-2025-6425
MEDIUM 4.3

An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between cont…

CVE-2025-6424
CRITICAL 9.8

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.1…

CVE-2025-6218
HIGH 7.8 KEV

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install…

CVE-2025-6192
HIGH 8.8

Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (C…

CVE-2025-6191
HIGH 8.8

Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML…

CVE-2025-43200
MEDIUM 4.2 KEV

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.…

CVE-2025-5986
MEDIUM 6.5

A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompti…

CVE-2025-49710
CRITICAL 9.8

An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4.

CVE-2025-49709
CRITICAL 9.8

Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.

CVE-2025-5959
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…

CVE-2025-5958
HIGH 8.8

Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2025-2884
MEDIUM 6.6

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with…

CVE-2025-47953
CRITICAL · éditeur

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47175
HIGH 7.8

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2025-47171
MEDIUM 6.7

Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.

CVE-2025-47169
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-47168
HIGH 7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-47167
CRITICAL · éditeur

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-47165
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-47164
CRITICAL · éditeur

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa