Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

26 089 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
26 089
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-10-02

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

26 089 entrées
CVE
CVE-2022-4926
MEDIUM 6.5

Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a cra…

CVE-2022-4925
MEDIUM 6.5

Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform header splitting via malicious n…

CVE-2022-4924
CRITICAL 9.6

Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the renderer process to potentially perform a san…

CVE-2022-4923
LOW 3.1

Inappropriate implementation in Omnibox in Google Chrome prior to 99.0.4844.51 allowed an attacker in a privileged network position to perform a man-in-the-mid…

CVE-2022-4922
MEDIUM 6.5

Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromiu…

CVE-2022-4921
HIGH 8.8

Use after free in Accessibility in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific UI gestures to perf…

CVE-2022-4920
CRITICAL 9.6

Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to poten…

CVE-2022-4919
HIGH 8.8

Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Ch…

CVE-2022-4918
HIGH 8.8

Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium secur…

CVE-2022-4917
MEDIUM 4.3

Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via…

CVE-2022-4916
HIGH 8.8

Use after free in Media in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium se…

CVE-2022-4915
MEDIUM 6.5

Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to perform domain spoofing via a crafted HTML…

CVE-2022-4914
HIGH 8.8

Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to poten…

CVE-2022-4913
MEDIUM 6.5

Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to spoof …

CVE-2022-4912
HIGH 8.8

Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2022-4911
MEDIUM 6.5

Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass content security policy via a crafted HTML…

CVE-2022-4910
MEDIUM 5.4

Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass navigation restrictions via a crafted HTML…

CVE-2022-4909
MEDIUM 6.3

Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially perform an ASLR bypass via a crafted HTML …

CVE-2022-4908
MEDIUM 4.3

Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak cross-origin data via a crafted HTML p…

CVE-2022-4907
HIGH 8.8

Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pag…

CVE-2022-4906
HIGH 8.8

Inappropriate implementation in Blink in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page…

CVE-2021-4324
MEDIUM 6.5

Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to read arbitrary files via a malicious file.…

CVE-2021-4323
MEDIUM 6.5

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious…

CVE-2021-4322
HIGH 8.8

Use after free in DevTools in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to execute arbitrar…

CVE-2021-4321
MEDIUM 4.3

Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium se…

CVE-2021-4320
HIGH 8.8

Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/wr…

CVE-2021-4319
HIGH 8.8

Use after free in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium sec…

CVE-2021-4318
HIGH 8.8

Object corruption in Blink in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (…

CVE-2021-4317
HIGH 8.8

Use after free in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium sec…

CVE-2021-4316
MEDIUM 4.3

Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium…

CVE-2023-3598
HIGH 8.8

Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

CVE-2023-3417
HIGH 7.5

Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while …

CVE-2023-36883
MEDIUM 4.3

Microsoft Edge for iOS Spoofing Vulnerability

CVE-2023-3600
HIGH · éditeur

During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerability affect…

CVE-2023-36884
HIGH 7.5 KEV

Windows Search Remote Code Execution Vulnerability

CVE-2023-35311
HIGH 8.8 KEV

Microsoft Outlook Security Feature Bypass Vulnerability

CVE-2023-33150
CRITICAL 9.6

Microsoft Office Security Feature Bypass Vulnerability

CVE-2023-36874
HIGH · éditeur KEV

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2023-36871
HIGH · éditeur

Azure Active Directory Security Feature Bypass Vulnerability

CVE-2023-35367
CRITICAL · éditeur

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2023-35366
CRITICAL · éditeur

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2023-35365
CRITICAL · éditeur

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2023-35364
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-35363
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-35362
HIGH · éditeur

Windows Clip Service Elevation of Privilege Vulnerability

CVE-2023-35361
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-35360
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-35358
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-35357
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-35356
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa