Vulnérabilités
Vulnérabilités des apps suivies
26 089 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 26 089
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-10-02
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-5728
During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerab… |
|
CVE-2023-5727
The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. … |
|
CVE-2023-5726
A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. … |
|
CVE-2023-5725
A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulner… |
|
CVE-2023-5724
Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119… |
|
CVE-2023-5721
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This … |
|
CVE-2023-5472
Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (… |
|
CVE-2023-5487
Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to… |
|
CVE-2023-5486
Inappropriate implementation in Input in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium… |
|
CVE-2023-5485
Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions via a crafted HTML p… |
|
CVE-2023-5484
Inappropriate implementation in Navigation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chr… |
|
CVE-2023-5483
Inappropriate implementation in Intents in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass content security policy via a crafted HTML … |
|
CVE-2023-5481
Inappropriate implementation in Downloads in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chro… |
|
CVE-2023-5479
Inappropriate implementation in Extensions API in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extensio… |
|
CVE-2023-5478
Inappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (… |
|
CVE-2023-5477
Inappropriate implementation in Installer in Google Chrome prior to 118.0.5993.70 allowed a local attacker to bypass discretionary access control via a crafted… |
|
CVE-2023-5476
Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… |
|
CVE-2023-5475
Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to b… |
|
CVE-2023-5474
Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to p… |
|
CVE-2023-5473
Use after free in Cast in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap c… |
|
CVE-2023-5218
Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… |
|
CVE-2023-36565
Microsoft Office Graphics Elevation of Privilege Vulnerability |
|
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w… |
|
CVE-2023-41774
CRITICAL · éditeur
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
|
CVE-2023-41773
CRITICAL · éditeur
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
|
CVE-2023-41772
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-41771
CRITICAL · éditeur
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
|
CVE-2023-41770
CRITICAL · éditeur
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
|
CVE-2023-41769
CRITICAL · éditeur
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
|
CVE-2023-41768
CRITICAL · éditeur
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
|
CVE-2023-41767
CRITICAL · éditeur
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
|
CVE-2023-41766
HIGH · éditeur
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability |
|
CVE-2023-41765
CRITICAL · éditeur
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
|
CVE-2023-38545
Hackerone: CVE-2023-38545 SOCKS5 heap buffer overflow |
|
CVE-2023-38171
HIGH · éditeur
Microsoft QUIC Denial of Service Vulnerability |
|
CVE-2023-38166
CRITICAL · éditeur
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |
|
CVE-2023-38159
HIGH · éditeur
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2023-38039
Hackerone: CVE-2023-38039 HTTP headers eat all memory |
|
CVE-2023-36902
HIGH · éditeur
Windows Runtime Remote Code Execution Vulnerability |
|
CVE-2023-36776
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-36743
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-36732
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-36731
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-36729
HIGH · éditeur
Named Pipe File System Elevation of Privilege Vulnerability |
|
CVE-2023-36726
HIGH · éditeur
Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability |
|
CVE-2023-36725
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-36724
HIGH · éditeur
Windows Power Management Service Information Disclosure Vulnerability |
|
CVE-2023-36723
HIGH · éditeur
Windows Container Manager Service Elevation of Privilege Vulnerability |
|
CVE-2023-36722
HIGH · éditeur
Active Directory Domain Services Information Disclosure Vulnerability |
|
CVE-2023-36721
HIGH · éditeur
Windows Error Reporting Service Elevation of Privilege Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.