Vulnérabilités
Vulnérabilités des apps suivies
25 929 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 929
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-29
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-47985
HIGH · éditeur
Windows Event Tracing Elevation of Privilege Vulnerability |
|
CVE-2025-47984
HIGH · éditeur
Windows GDI Information Disclosure Vulnerability |
|
CVE-2025-47982
HIGH · éditeur
Windows Storage VSP Driver Elevation of Privilege Vulnerability |
|
CVE-2025-47981
CRITICAL · éditeur
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability |
|
CVE-2025-47980
CRITICAL · éditeur
Windows Imaging Component Information Disclosure Vulnerability |
|
CVE-2025-47978
HIGH · éditeur
Windows Kerberos Denial of Service Vulnerability |
|
CVE-2025-47976
HIGH · éditeur
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
|
CVE-2025-47975
HIGH · éditeur
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability |
|
CVE-2025-47973
HIGH · éditeur
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
|
CVE-2025-47972
HIGH · éditeur
Windows Input Method Editor (IME) Elevation of Privilege Vulnerability |
|
CVE-2025-47971
HIGH · éditeur
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
|
CVE-2025-47159
HIGH · éditeur
Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability |
|
CVE-2025-33054
HIGH · éditeur
Remote Desktop Spoofing Vulnerability |
|
CVE-2025-26636
HIGH · éditeur
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2024-36357
CRITICAL · éditeur
AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue |
|
CVE-2024-36350
CRITICAL · éditeur
AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue |
|
CVE-2025-6554
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium secur… |
|
CVE-2025-32462
LOW 2.8
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute commands on … |
|
CVE-2025-6557
Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specifi… |
|
CVE-2025-6556
Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTM… |
|
CVE-2025-6555
Use after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (… |
|
CVE-2025-6436
Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-6435
If a user saved a response from the Network tab in Devtools using the Save As context menu option, that file may not have been saved with the `.download` file … |
|
CVE-2025-6434
MEDIUM 4.3
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker… |
|
CVE-2025-6433
CRITICAL 9.8
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would… |
|
CVE-2025-6432
HIGH 8.6
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not respondin… |
|
CVE-2025-6430
MEDIUM 6.1
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<… |
|
CVE-2025-6429
MEDIUM 6.5
Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypas… |
|
CVE-2025-6427
CRITICAL 9.1
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connectio… |
|
CVE-2025-6426
HIGH 8.8
The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of… |
|
CVE-2025-6425
MEDIUM 4.3
An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between cont… |
|
CVE-2025-6424
CRITICAL 9.8
A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.1… |
|
CVE-2025-6218
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install… |
|
CVE-2025-6192
Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (C… |
|
CVE-2025-6191
Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML… |
|
CVE-2025-43200
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.… |
|
CVE-2025-5986
MEDIUM 6.5
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompti… |
|
CVE-2025-49710
CRITICAL 9.8
An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4. |
|
CVE-2025-49709
CRITICAL 9.8
Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4. |
|
CVE-2025-5959
Type Confusion in V8 in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch… |
|
CVE-2025-5958
Use after free in Media in Google Chrome prior to 137.0.7151.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
|
CVE-2025-2884
MEDIUM 6.6
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with… |
|
CVE-2025-47953
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-47175
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. |
|
CVE-2025-47171
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. |
|
CVE-2025-47169
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2025-47168
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2025-47167
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-47165
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-47164
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.