Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 929 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 929
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-09-29

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 929 entrées
CVE
CVE-2025-31202
MEDIUM 5.5

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, vision…

CVE-2025-31197
MEDIUM 5.7

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ve…

CVE-2025-30445
MEDIUM 6.5

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.…

CVE-2025-24271
MEDIUM 5.4

An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sono…

CVE-2025-24270
MEDIUM 5.7

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7…

CVE-2025-24252
HIGH 8.8

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS…

CVE-2025-24251
MEDIUM 6.5

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ve…

CVE-2025-24206
HIGH 7.7

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS…

CVE-2025-24179
MEDIUM 5.7

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, ma…

CVE-2022-47112
LOW 2.5

7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.

CVE-2022-47111
LOW 2.5

7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected.

CVE-2025-3620
HIGH 8.8

Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2025-3619
HIGH 8.8

Heap buffer overflow in Codecs in Google Chrome on Windows prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafte…

CVE-2025-31201
CRITICAL 9.8 KEV

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.…

CVE-2025-31200
CRITICAL 9.8 KEV

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, …

CVE-2025-1292
MEDIUM 6.7

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 122.0.6261.132 stable on Cr50 Boards allows an attacker with root access to gain persistence …

CVE-2025-1122
MEDIUM 6.7

Out-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to gain persistence and …

CVE-2025-3523
MEDIUM 6.4

When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering ove…

CVE-2025-3522
MEDIUM 6.3

Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird a…

CVE-2025-2830
MEDIUM 6.3

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when t…

CVE-2025-3608
MEDIUM 6.5

A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This …

CVE-2025-29822
HIGH 7.8

Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-29816
HIGH 7.5

Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.

CVE-2025-29805
HIGH 7.5

Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.

CVE-2025-27751
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-27750
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-27747
HIGH 7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-26687
HIGH · éditeur

Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-26642
HIGH 7.8

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-29824
HIGH · éditeur KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-29812
HIGH · éditeur

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-29811
HIGH · éditeur

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

CVE-2025-29810
HIGH · éditeur

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2025-29809
HIGH · éditeur

Windows Kerberos Security Feature Bypass Vulnerability

CVE-2025-29808
HIGH · éditeur

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2025-27742
HIGH · éditeur

NTFS Information Disclosure Vulnerability

CVE-2025-27741
HIGH · éditeur

NTFS Elevation of Privilege Vulnerability

CVE-2025-27740
HIGH · éditeur

Active Directory Certificate Services Elevation of Privilege Vulnerability

CVE-2025-27739
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-27738
HIGH · éditeur

Windows Resilient File System (ReFS) Information Disclosure Vulnerability

CVE-2025-27737
HIGH · éditeur

Windows Security Zone Mapping Security Feature Bypass Vulnerability

CVE-2025-27736
HIGH · éditeur

Windows Power Dependency Coordinator Information Disclosure Vulnerability

CVE-2025-27735
HIGH · éditeur

Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability

CVE-2025-27733
HIGH · éditeur

NTFS Elevation of Privilege Vulnerability

CVE-2025-27732
HIGH · éditeur

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-27731
HIGH · éditeur

Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability

CVE-2025-27730
HIGH · éditeur

Windows Digital Media Elevation of Privilege Vulnerability

CVE-2025-27729
HIGH · éditeur

Windows Shell Remote Code Execution Vulnerability

CVE-2025-27728
HIGH · éditeur

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

CVE-2025-27727
HIGH · éditeur

Windows Installer Elevation of Privilege Vulnerability

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa