Vulnérabilités
Vulnérabilités des apps suivies
25 934 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 934
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-29
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-24081
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-24079
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2025-24078
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
|
CVE-2025-24075
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-26645
CRITICAL · éditeur
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2025-26634
HIGH · éditeur
Windows Core Messaging Elevation of Privileges Vulnerability |
|
CVE-2025-25008
HIGH · éditeur
Windows Server Elevation of Privilege Vulnerability |
|
CVE-2025-24997
HIGH · éditeur
DirectX Graphics Kernel File Denial of Service Vulnerability |
|
CVE-2025-24996
HIGH · éditeur
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-24995
HIGH · éditeur
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24994
HIGH · éditeur
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
|
CVE-2025-24992
HIGH · éditeur
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24991
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24988
HIGH · éditeur
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24987
HIGH · éditeur
Windows USB Video Class System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24985
Windows Fast FAT File System Driver Remote Code Execution Vulnerability |
|
CVE-2025-24984
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24983
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-24855
numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is… |
|
CVE-2025-24084
CRITICAL · éditeur
Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability |
|
CVE-2025-24076
HIGH · éditeur
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
|
CVE-2025-24072
HIGH · éditeur
Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability |
|
CVE-2025-24071
HIGH · éditeur
Microsoft Windows File Explorer Spoofing Vulnerability |
|
CVE-2025-24067
HIGH · éditeur
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24066
HIGH · éditeur
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24064
CRITICAL · éditeur
Windows Domain Name Service Remote Code Execution Vulnerability |
|
CVE-2025-24061
HIGH · éditeur
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2025-24059
HIGH · éditeur
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24056
HIGH · éditeur
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-24055
HIGH · éditeur
Windows USB Video Class System Driver Information Disclosure Vulnerability |
|
CVE-2025-24054
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-24051
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-24050
HIGH · éditeur
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-24048
HIGH · éditeur
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2025-24046
HIGH · éditeur
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-24045
CRITICAL · éditeur
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2025-24044
HIGH · éditeur
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-24035
CRITICAL · éditeur
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2025-21247
HIGH · éditeur
MapUrlToZone Security Feature Bypass Vulnerability |
|
CVE-2025-21180
HIGH · éditeur
Windows exFAT File System Remote Code Execution Vulnerability |
|
CVE-2024-9157
HIGH · éditeur
Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading Vulnerability |
|
CVE-2024-55549
xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue |
|
CVE-2025-2137
Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chr… |
|
CVE-2025-2136
Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (… |
|
CVE-2025-2135
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… |
|
CVE-2025-1920
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… |
|
CVE-2025-26696
HIGH 7.0
Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown… |
|
CVE-2025-26695
MEDIUM 5.3
When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested emai… |
|
CVE-2024-54560
A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A malicious app may be ab… |
|
CVE-2024-54558
A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be abl… |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.