Vulnérabilités
Vulnérabilités des apps suivies
25 946 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 946
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-29
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2024-2631
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium… |
|
CVE-2024-2630
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chrom… |
|
CVE-2024-2629
Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium securi… |
|
CVE-2024-2628
Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium… |
|
CVE-2024-2627
Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
|
CVE-2024-2626
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML p… |
|
CVE-2024-2625
Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page… |
|
CVE-2024-2616
To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects F… |
|
CVE-2024-2614
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2024-2612
If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code … |
|
CVE-2024-2611
A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox… |
|
CVE-2024-2610
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability a… |
|
CVE-2024-2609
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerabi… |
|
CVE-2024-2608
`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underalloc… |
|
CVE-2024-2607
Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other opera… |
|
CVE-2024-2606
LOW 3.7
Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Fi… |
|
CVE-2024-2605
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows … |
|
CVE-2023-5388
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data… |
|
CVE-2024-23298
MEDIUM 5.5
A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks. |
|
CVE-2024-26246
LOW 3.9
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
|
CVE-2023-42938
HIGH 7.8
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges. |
|
CVE-2024-2400
Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted H… |
|
CVE-2024-26204
HIGH 7.5
Outlook for Android Information Disclosure Vulnerability |
|
CVE-2024-21390
HIGH 7.1
Microsoft Authenticator Elevation of Privilege Vulnerability |
|
CVE-2024-26197
HIGH · éditeur
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
|
CVE-2024-26190
HIGH · éditeur
Microsoft QUIC Denial of Service Vulnerability |
|
CVE-2024-26185
HIGH · éditeur
Windows Compressed Folder Tampering Vulnerability |
|
CVE-2024-26182
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-26181
HIGH · éditeur
Windows Kernel Denial of Service Vulnerability |
|
CVE-2024-26178
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-26177
HIGH · éditeur
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2024-26176
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-26174
HIGH · éditeur
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2024-26173
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-26170
HIGH · éditeur
Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability |
|
CVE-2024-26169
Windows Error Reporting Service Elevation of Privilege Vulnerability |
|
CVE-2024-26166
HIGH · éditeur
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-26162
HIGH · éditeur
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2024-26161
HIGH · éditeur
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-26160
HIGH · éditeur
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability |
|
CVE-2024-26159
HIGH · éditeur
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2024-21451
HIGH · éditeur
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2024-21450
HIGH · éditeur
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21446
HIGH · éditeur
NTFS Elevation of Privilege Vulnerability |
|
CVE-2024-21445
HIGH · éditeur
Windows USB Print Driver Elevation of Privilege Vulnerability |
|
CVE-2024-21444
HIGH · éditeur
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21443
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-21442
HIGH · éditeur
Windows USB Print Driver Elevation of Privilege Vulnerability |
|
CVE-2024-21441
HIGH · éditeur
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2024-21440
HIGH · éditeur
Microsoft ODBC Driver Remote Code Execution Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.