Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 741 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 372 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 741
Activement exploitées
372
Fenêtre de publication
1997-01-01 → 2026-09-17

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 741 entrées
CVE
CVE-2026-71342
HIGH 7.0

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-71341
MEDIUM 5.5

Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.

CVE-2026-71340
HIGH 7.0

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

CVE-2026-71339
MEDIUM 6.7

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-71338
MEDIUM 6.4

Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.

CVE-2026-71337
HIGH 7.8

Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.

CVE-2026-71336
HIGH 8.8

Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.

CVE-2026-71334
HIGH 7.8

Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.

CVE-2026-71333
HIGH 7.0

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-71332
HIGH 7.0

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.

CVE-2026-71330
HIGH 7.5

Exposure of sensitive system information to an unauthorized control sphere in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to dis…

CVE-2026-71329
MEDIUM 6.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.

CVE-2026-70587
HIGH 7.5

Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.

CVE-2026-70586
HIGH 8.8

Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code over a network.

CVE-2026-70585
HIGH 7.0

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.

CVE-2026-70584
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

CVE-2026-70581
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70577
HIGH 7.0

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

CVE-2026-70574
HIGH 7.8

Out-of-bounds read in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-70573
HIGH 7.0

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70572
HIGH 7.8

Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70569
HIGH 7.8

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.

CVE-2026-70568
HIGH 7.0

Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70567
HIGH 7.0

Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70565
HIGH 7.0

Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally.

CVE-2026-70564
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-70563
HIGH 8.1

Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-70562
HIGH 7.0

Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.

CVE-2026-70342
HIGH 8.1

Use after free in Windows Ancillary Function Driver for WinSock allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-70296
CRITICAL 9.8

Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

CVE-2026-70290
MEDIUM 5.5

Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.

CVE-2026-70289
HIGH 7.8

Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

CVE-2026-70283
HIGH 7.0

Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-70203
HIGH 8.8

Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network.

CVE-2026-70145
MEDIUM 5.5

Out-of-bounds read in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

CVE-2026-70124
MEDIUM 5.9

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

CVE-2026-70091
MEDIUM 5.9

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over…

CVE-2026-70065
HIGH 7.5

Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

CVE-2026-70019
MEDIUM 6.5

Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network.

CVE-2026-69989
HIGH 8.1

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

CVE-2026-69930
MEDIUM 5.9

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

CVE-2026-69929
MEDIUM 5.9

Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network.

CVE-2026-69921
HIGH 7.8

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

CVE-2026-69911
HIGH 7.0

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

CVE-2026-69910
CRITICAL 9.8

Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.

CVE-2026-69907
HIGH 7.8

Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.

CVE-2026-69906
HIGH 8.2

Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVE-2026-69900
HIGH 7.8

Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-69896
HIGH 7.0

Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

CVE-2026-69895
MEDIUM 4.7

Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.