Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

26 089 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
26 089
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-10-02

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

26 089 entrées
CVE
CVE-2023-5728
HIGH · éditeur

During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerab…

CVE-2023-5727
MEDIUM 6.5

The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. …

CVE-2023-5726
MEDIUM 4.3

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. …

CVE-2023-5725
MEDIUM · éditeur

A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulner…

CVE-2023-5724
HIGH 7.5

Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119…

CVE-2023-5721
MEDIUM 4.3

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This …

CVE-2023-5472
HIGH 8.8

Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (…

CVE-2023-5487
MEDIUM 6.5

Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to…

CVE-2023-5486
MEDIUM 4.3

Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium…

CVE-2023-5485
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML p…

CVE-2023-5484
MEDIUM 6.5

Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chr…

CVE-2023-5483
MEDIUM 6.5

Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML …

CVE-2023-5481
MEDIUM 6.5

Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chro…

CVE-2023-5479
MEDIUM 6.5

Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extensio…

CVE-2023-5478
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (…

CVE-2023-5477
MEDIUM 4.3

Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted…

CVE-2023-5476
HIGH 8.8

Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

CVE-2023-5475
MEDIUM 6.5

Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to b…

CVE-2023-5474
HIGH 8.8

Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to p…

CVE-2023-5473
MEDIUM 6.3

Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap c…

CVE-2023-5218
HIGH 8.8

Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

CVE-2023-36565
HIGH · éditeur

Microsoft Office Graphics Elevation of Privilege Vulnerability

CVE-2023-44487
HIGH 7.5 KEV

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w…

CVE-2023-41774
CRITICAL · éditeur

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41773
CRITICAL · éditeur

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41772
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2023-41771
CRITICAL · éditeur

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41770
CRITICAL · éditeur

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41769
CRITICAL · éditeur

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41768
CRITICAL · éditeur

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41767
CRITICAL · éditeur

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-41766
HIGH · éditeur

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

CVE-2023-41765
CRITICAL · éditeur

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-38545
HIGH · éditeur

Hackerone: CVE-2023-38545 SOCKS5 heap buffer overflow

CVE-2023-38171
HIGH · éditeur

Microsoft QUIC Denial of Service Vulnerability

CVE-2023-38166
CRITICAL · éditeur

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVE-2023-38159
HIGH · éditeur

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2023-38039
LOW · éditeur

Hackerone: CVE-2023-38039 HTTP headers eat all memory

CVE-2023-36902
HIGH · éditeur

Windows Runtime Remote Code Execution Vulnerability

CVE-2023-36776
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2023-36743
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2023-36732
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2023-36731
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2023-36729
HIGH · éditeur

Named Pipe File System Elevation of Privilege Vulnerability

CVE-2023-36726
HIGH · éditeur

Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability

CVE-2023-36725
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-36724
HIGH · éditeur

Windows Power Management Service Information Disclosure Vulnerability

CVE-2023-36723
HIGH · éditeur

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2023-36722
HIGH · éditeur

Active Directory Domain Services Information Disclosure Vulnerability

CVE-2023-36721
HIGH · éditeur

Windows Error Reporting Service Elevation of Privilege Vulnerability

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa