Vulnérabilités
Vulnérabilités des apps suivies
25 929 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 929
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-29
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-31202
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, vision… |
|
CVE-2025-31197
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ve… |
|
CVE-2025-30445
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.… |
|
CVE-2025-24271
An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sono… |
|
CVE-2025-24270
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7… |
|
CVE-2025-24252
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS… |
|
CVE-2025-24251
The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ve… |
|
CVE-2025-24206
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS… |
|
CVE-2025-24179
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, ma… |
|
CVE-2022-47112
LOW 2.5
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected. |
|
CVE-2022-47111
LOW 2.5
7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected. |
|
CVE-2025-3620
Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2025-3619
Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafte… |
|
CVE-2025-31201
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.… |
|
CVE-2025-31200
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, … |
|
CVE-2025-1292
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence … |
|
CVE-2025-1122
Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and … |
|
CVE-2025-3523
MEDIUM 6.4
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering ove… |
|
CVE-2025-3522
MEDIUM 6.3
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird a… |
|
CVE-2025-2830
MEDIUM 6.3
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when t… |
|
CVE-2025-3608
MEDIUM 6.5
A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This … |
|
CVE-2025-29822
Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-29816
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2025-29805
HIGH 7.5
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. |
|
CVE-2025-27751
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-27750
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-27747
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2025-26687
HIGH · éditeur
Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. |
|
CVE-2025-26642
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-29824
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-29812
HIGH · éditeur
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-29811
HIGH · éditeur
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
|
CVE-2025-29810
HIGH · éditeur
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2025-29809
HIGH · éditeur
Windows Kerberos Security Feature Bypass Vulnerability |
|
CVE-2025-29808
HIGH · éditeur
Windows Cryptographic Services Information Disclosure Vulnerability |
|
CVE-2025-27742
HIGH · éditeur
NTFS Information Disclosure Vulnerability |
|
CVE-2025-27741
HIGH · éditeur
NTFS Elevation of Privilege Vulnerability |
|
CVE-2025-27740
HIGH · éditeur
Active Directory Certificate Services Elevation of Privilege Vulnerability |
|
CVE-2025-27739
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-27738
HIGH · éditeur
Windows Resilient File System (ReFS) Information Disclosure Vulnerability |
|
CVE-2025-27737
HIGH · éditeur
Windows Security Zone Mapping Security Feature Bypass Vulnerability |
|
CVE-2025-27736
HIGH · éditeur
Windows Power Dependency Coordinator Information Disclosure Vulnerability |
|
CVE-2025-27735
HIGH · éditeur
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability |
|
CVE-2025-27733
HIGH · éditeur
NTFS Elevation of Privilege Vulnerability |
|
CVE-2025-27732
HIGH · éditeur
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-27731
HIGH · éditeur
Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability |
|
CVE-2025-27730
HIGH · éditeur
Windows Digital Media Elevation of Privilege Vulnerability |
|
CVE-2025-27729
HIGH · éditeur
Windows Shell Remote Code Execution Vulnerability |
|
CVE-2025-27728
HIGH · éditeur
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
|
CVE-2025-27727
HIGH · éditeur
Windows Installer Elevation of Privilege Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.