Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 741 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 372 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 741
Activement exploitées
372
Fenêtre de publication
1997-01-01 → 2026-09-17

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 741 entrées
CVE
CVE-2026-72977
MEDIUM 6.5

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

CVE-2026-72976
MEDIUM 5.0

Out-of-bounds read in Microsoft Office Word allows an authorized attacker to disclose information locally.

CVE-2026-72975
MEDIUM 6.5

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

CVE-2026-72973
HIGH 8.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-72972
HIGH 8.8

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.

CVE-2026-72967
HIGH 7.8

Heap-based buffer overflow in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

CVE-2026-72966
MEDIUM 5.5

Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.

CVE-2026-72965
HIGH 7.8

Use after free in Windows WebClient Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72964
MEDIUM 5.5

Missing authentication for critical function in Windows Internet Connection Sharing (ICS) allows an authorized attacker to perform tampering locally.

CVE-2026-72963
HIGH 7.0

Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.

CVE-2026-72962
HIGH 8.2

Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-72961
HIGH 8.2

Out-of-bounds read in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

CVE-2026-72960
HIGH 8.8

Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

CVE-2026-72959
HIGH 8.8

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-72958
HIGH 8.2

Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.

CVE-2026-72957
HIGH 7.8

Heap-based buffer overflow in Windows Deployment Services allows an authorized attacker to execute code locally.

CVE-2026-72954
HIGH 7.5

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

CVE-2026-72953
HIGH 7.8

Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-72952
HIGH 7.0

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.

CVE-2026-72950
HIGH 8.8

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVE-2026-72949
HIGH 7.5

Null pointer dereference in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to deny service over a network.

CVE-2026-72948
MEDIUM 6.7

Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-72947
MEDIUM 6.4

Integer underflow (wrap or wraparound) in Windows File History Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72946
HIGH 7.8

Heap-based buffer overflow in Storage Port Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-72945
MEDIUM 5.5

Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.

CVE-2026-72944
HIGH 7.8

Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72943
HIGH 7.5

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

CVE-2026-72942
MEDIUM 6.5

Out-of-bounds read in Windows Spaceport.sys allows an unauthorized attacker to disclose information over a network.

CVE-2026-72941
HIGH 7.8

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-72940
HIGH 8.8

Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network.

CVE-2026-72939
MEDIUM 6.5

Null pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service over a network.

CVE-2026-72937
MEDIUM 5.5

Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.

CVE-2026-72936
HIGH 8.1

Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network.

CVE-2026-72935
MEDIUM 6.7

Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

CVE-2026-72933
HIGH 8.8

Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.

CVE-2026-72932
HIGH 7.5

Buffer over-read in Windows Message Queuing Queue Manager allows an unauthorized attacker to disclose information over a network.

CVE-2026-72931
MEDIUM 4.7

Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.

CVE-2026-72930
HIGH 7.0

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.

CVE-2026-72929
HIGH 7.8

Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-72928
HIGH 7.5

Use after free in Windows DNS allows an authorized attacker to execute code over a network.

CVE-2026-72927
MEDIUM 6.7

Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.

CVE-2026-72926
HIGH 7.0

Use after free in Windows Internet Connection Sharing (ICS) allows an authorized attacker to elevate privileges locally.

CVE-2026-71353
HIGH 7.0

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-71352
HIGH 8.8

Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.

CVE-2026-71351
HIGH 7.0

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVE-2026-71350
MEDIUM 6.8

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-71349
MEDIUM 6.8

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-71348
MEDIUM 6.8

Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-71345
HIGH 7.8

Out-of-bounds write in Windows Spaceport.sys allows an authorized attacker to execute code locally.

CVE-2026-71343
HIGH 7.8

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.