Vulnérabilités
Vulnérabilités des apps suivies
25 940 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 940
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-29
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-21406
HIGH · éditeur
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21379
CRITICAL · éditeur
DHCP Client Service Remote Code Execution Vulnerability |
|
CVE-2025-21377
HIGH · éditeur
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-21376
CRITICAL · éditeur
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
|
CVE-2025-21375
HIGH · éditeur
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-21373
HIGH · éditeur
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2025-21371
HIGH · éditeur
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21369
HIGH · éditeur
Microsoft Digest Authentication Remote Code Execution Vulnerability |
|
CVE-2025-21368
HIGH · éditeur
Microsoft Digest Authentication Remote Code Execution Vulnerability |
|
CVE-2025-21367
HIGH · éditeur
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-21359
HIGH · éditeur
Windows Kernel Security Feature Bypass Vulnerability |
|
CVE-2025-21358
HIGH · éditeur
Windows Core Messaging Elevation of Privileges Vulnerability |
|
CVE-2025-21352
HIGH · éditeur
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
|
CVE-2025-21351
HIGH · éditeur
Windows Active Directory Domain Services API Denial of Service Vulnerability |
|
CVE-2025-21350
HIGH · éditeur
Windows Kerberos Denial of Service Vulnerability |
|
CVE-2025-21349
HIGH · éditeur
Windows Remote Desktop Configuration Service Tampering Vulnerability |
|
CVE-2025-21347
HIGH · éditeur
Windows Deployment Services Denial of Service Vulnerability |
|
CVE-2025-21337
HIGH · éditeur
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2025-21254
HIGH · éditeur
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
|
CVE-2025-21216
HIGH · éditeur
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
|
CVE-2025-21212
HIGH · éditeur
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
|
CVE-2025-21208
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
|
CVE-2025-21201
HIGH · éditeur
Windows Telephony Server Remote Code Execution Vulnerability |
|
CVE-2025-21200
HIGH · éditeur
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21190
HIGH · éditeur
Windows Telephony Service Remote Code Execution Vulnerability |
|
CVE-2025-21184
HIGH · éditeur
Windows Core Messaging Elevation of Privileges Vulnerability |
|
CVE-2025-21183
HIGH · éditeur
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability |
|
CVE-2025-21182
HIGH · éditeur
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability |
|
CVE-2025-21181
HIGH · éditeur
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2025-21179
HIGH · éditeur
DHCP Client Service Denial of Service Vulnerability |
|
CVE-2025-24200
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 1… |
|
CVE-2024-54658
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1… |
|
CVE-2024-27859
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.… |
|
CVE-2025-21253
Microsoft Edge for IOS and Android Spoofing Vulnerability |
|
CVE-2025-0451
Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI … |
|
CVE-2025-0445
Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… |
|
CVE-2025-0444
Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrom… |
|
CVE-2025-1020
Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-1019
The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. … |
|
CVE-2025-1018
The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential sp… |
|
CVE-2025-1017
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption a… |
|
CVE-2025-1016
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bug… |
|
CVE-2025-1015
MEDIUM 5.4
The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malici… |
|
CVE-2025-1014
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Fir… |
|
CVE-2025-1013
A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vu… |
|
CVE-2025-1012
A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135, Firefox ESR 115.20, Firefox ESR 128.7,… |
|
CVE-2025-1011
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vul… |
|
CVE-2025-1010
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability was fixed in Firefo… |
|
CVE-2025-1009
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 135, … |
|
CVE-2025-0510
MEDIUM 6.5
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vu… |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.