Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

26 089 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
26 089
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-10-02

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

26 089 entrées
CVE
CVE-2023-41105
HIGH 7.5

An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly…

CVE-2023-4431
HIGH 8.1

Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted H…

CVE-2023-4430
HIGH 8.8

Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch…

CVE-2023-4429
HIGH 8.8

Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch…

CVE-2023-4428
HIGH 8.1

Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTM…

CVE-2023-4427
HIGH 8.1

Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML…

CVE-2022-48566
MEDIUM 5.9

An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variab…

CVE-2022-48565
CRITICAL 9.8

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoi…

CVE-2022-48564
MEDIUM 6.5

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property Li…

CVE-2022-48560
HIGH 7.5

A use-after-free exists in Python through 3.9 via heappushpop in heapq.

CVE-2023-4369
HIGH 8.8

Insufficient data validation in Systems Extensions in Google Chrome on ChromeOS prior to 116.0.5845.120 allowed an attacker who convinced a user to install a m…

CVE-2023-4368
HIGH 8.8

Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious exten…

CVE-2023-4367
MEDIUM 6.5

Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious exten…

CVE-2023-4366
HIGH 8.8

Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially e…

CVE-2023-4365
MEDIUM 4.3

Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. …

CVE-2023-4364
MEDIUM 4.3

Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTM…

CVE-2023-4363
MEDIUM 4.3

Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via…

CVE-2023-4362
HIGH 8.8

Heap buffer overflow in Mojom IDL in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process and gained control…

CVE-2023-4361
MEDIUM 5.3

Inappropriate implementation in Autofill in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to bypass Autofill restrictions via a cra…

CVE-2023-4360
MEDIUM 4.3

Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chro…

CVE-2023-4359
MEDIUM 5.3

Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 116.0.5845.96 allowed a remote attacker to potentially spoof elements of the secu…

CVE-2023-4358
HIGH 8.8

Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2023-4357
HIGH 8.8

Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a cr…

CVE-2023-4356
HIGH 8.8

Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has convinced a user to engage in specific UI interaction to pote…

CVE-2023-4355
HIGH 8.8

Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

CVE-2023-4354
HIGH 8.8

Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit …

CVE-2023-4353
HIGH 8.8

Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.…

CVE-2023-4352
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

CVE-2023-4351
HIGH 8.8

Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap cor…

CVE-2023-4350
MEDIUM 6.5

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of th…

CVE-2023-4349
HIGH 8.8

Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafte…

CVE-2023-2312
HIGH 8.8

Use after free in Offline in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially …

CVE-2023-38898
MEDIUM 5.3

An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by th…

CVE-2023-39214
HIGH 7.6

Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.

CVE-2023-39218
MEDIUM 6.1

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

CVE-2023-38254
MEDIUM 6.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2023-38186
HIGH 8.8

Windows Mobile Device Management Elevation of Privilege Vulnerability

CVE-2023-38184
HIGH 7.5

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVE-2023-38172
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2023-36914
MEDIUM 5.5

Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability

CVE-2023-36913
MEDIUM 6.5

Microsoft Message Queuing Information Disclosure Vulnerability

CVE-2023-36912
HIGH 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2023-36911
CRITICAL 9.8

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2023-36910
CRITICAL 9.8

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2023-36909
MEDIUM 6.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2023-36908
MEDIUM 6.5

Windows Hyper-V Information Disclosure Vulnerability

CVE-2023-36907
MEDIUM 5.5

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2023-36906
MEDIUM 5.5

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2023-36905
MEDIUM 5.5

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

CVE-2023-36904
HIGH 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa