Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 929 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 929
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-09-29

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 929 entrées
CVE
CVE-2025-5269
HIGH 8.1

Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort t…

CVE-2025-5268
HIGH 8.1

Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption…

CVE-2025-5267
MEDIUM 5.4

A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in …

CVE-2025-5266
MEDIUM 4.3

Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed…

CVE-2025-5265
MEDIUM 4.8

Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially lead…

CVE-2025-5264
MEDIUM 4.8

Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leadin…

CVE-2025-5263
MEDIUM 4.3

Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability was fixed…

CVE-2025-5262
HIGH 7.5

A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memo…

CVE-2025-5020
MEDIUM 4.3

Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTT…

CVE-2025-31262
MEDIUM 5.5

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, w…

CVE-2025-31185
LOW 3.3

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without auth…

CVE-2025-24189
HIGH 8.8

The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchO…

CVE-2025-24184
MEDIUM 5.5

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, tvOS 18.3, visionOS …

CVE-2025-24183
MEDIUM 5.5

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local user may be able to…

CVE-2025-4919
HIGH 8.8

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 1…

CVE-2025-4918
CRITICAL 9.8

An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 1…

CVE-2025-4664
MEDIUM 4.3

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page.…

CVE-2025-3932
MEDIUM 6.5

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accesse…

CVE-2025-3909
HIGH 8.1

Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested ema…

CVE-2025-3875
HIGH 7.5

Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From hea…

CVE-2025-32704
HIGH 8.4

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-30388
HIGH · éditeur

Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

CVE-2025-30386
CRITICAL · éditeur

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-30383
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-30381
HIGH 7.8

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-30379
HIGH 7.8

Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-30377
HIGH 8.4

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-30376
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-30375
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-29979
HIGH 7.8

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-29977
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-32709
HIGH · éditeur KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-32707
HIGH · éditeur

NTFS Elevation of Privilege Vulnerability

CVE-2025-32706
HIGH · éditeur KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-32701
HIGH · éditeur KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-30400
HIGH · éditeur KEV

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-30397
HIGH · éditeur KEV

Scripting Engine Memory Corruption Vulnerability

CVE-2025-30394
HIGH · éditeur

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

CVE-2025-30385
HIGH · éditeur

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-29974
HIGH · éditeur

Windows Kernel Information Disclosure Vulnerability

CVE-2025-29971
HIGH · éditeur

Web Threat Defense (WTD.sys) Denial of Service Vulnerability

CVE-2025-29970
HIGH · éditeur

Microsoft Brokering File System Elevation of Privilege Vulnerability

CVE-2025-29969
HIGH · éditeur

MS-EVEN RPC Remote Code Execution Vulnerability

CVE-2025-29968
HIGH · éditeur

Active Directory Certificate Services (AD CS) Denial of Service Vulnerability

CVE-2025-29967
CRITICAL · éditeur

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-29966
CRITICAL · éditeur

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-29964
HIGH · éditeur

Windows Media Remote Code Execution Vulnerability

CVE-2025-29963
HIGH · éditeur

Windows Media Remote Code Execution Vulnerability

CVE-2025-29962
HIGH · éditeur

Windows Media Remote Code Execution Vulnerability

CVE-2025-29961
HIGH · éditeur

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa