Vulnérabilités
Vulnérabilités des apps suivies
25 929 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 929
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-29
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-26637
HIGH · éditeur
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2025-26635
HIGH · éditeur
Windows Hello Security Feature Bypass Vulnerability |
|
CVE-2025-24074
HIGH · éditeur
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-24073
HIGH · éditeur
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-24062
HIGH · éditeur
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-24060
HIGH · éditeur
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-24058
HIGH · éditeur
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-21222
HIGH · éditeur
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21221
HIGH · éditeur
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21205
HIGH · éditeur
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21204
HIGH · éditeur
Windows Process Activation Elevation of Privilege Vulnerability |
|
CVE-2025-21203
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-21197
HIGH · éditeur
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-21191
HIGH · éditeur
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability |
|
CVE-2025-21174
HIGH · éditeur
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
|
CVE-2025-29796
MEDIUM 4.7
User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2025-25001
MEDIUM 4.3
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perf… |
|
CVE-2025-31334
MEDIUM 6.8
Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR v… |
|
CVE-2025-3074
Inappropriate implementation in Downloads in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Ch… |
|
CVE-2025-3073
Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestur… |
|
CVE-2025-3072
Inappropriate implementation in Custom Tabs in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI ges… |
|
CVE-2025-3071
Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI ges… |
|
CVE-2025-3070
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via … |
|
CVE-2025-3069
Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML… |
|
CVE-2025-3068
Inappropriate implementation in Intents in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a craf… |
|
CVE-2025-3067
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in spec… |
|
CVE-2025-3066
Use after free in Site Isolation in Google Chrome prior to 135.0.7049.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… |
|
CVE-2025-3035
MEDIUM 5.3
By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This v… |
|
CVE-2025-3034
Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-3033
After selecting a malicious Windows `.url` shortcut from the local filesystem, an unexpected file could be uploaded. *This bug only affects Firefox on Window… |
|
CVE-2025-3032
Leaking of file descriptors from the fork server to web content processes could allow for privilege escalation attacks. This vulnerability was fixed in Firefox… |
|
CVE-2025-3031
An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbird 137. |
|
CVE-2025-3030
Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption a… |
|
CVE-2025-3029
A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerabilit… |
|
CVE-2025-3028
JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firef… |
|
CVE-2025-26416
CRITICAL · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22439
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22435
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22434
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22433
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22431
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22430
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22429
CRITICAL · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22428
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22427
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22423
CRITICAL · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22422
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22421
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22419
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-22418
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.