Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

26 363 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
26 363
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-10-06

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

26 363 entrées
CVE
CVE-2023-20755
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-20754
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-42703
MEDIUM · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-28350
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-29256
HIGH · éditeur KEV

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-0948
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-36539
MEDIUM 5.3

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVE-2023-34658
MEDIUM 5.3

Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController.

CVE-2023-3422
HIGH 8.8

Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially …

CVE-2023-3421
HIGH 8.8

Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2023-3420
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2023-36632
HIGH 7.5

The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling …

CVE-2023-32395
MEDIUM 5.5

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may …

CVE-2023-32353
HIGH 7.8

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to elevate privileges.

CVE-2023-32351
HIGH 7.8

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to gain elevated privileges.

CVE-2023-34417
CRITICAL 9.8

Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h…

CVE-2023-34416
CRITICAL 9.8

Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume t…

CVE-2023-34414
LOW 3.1

The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks tha…

CVE-2023-29545
MEDIUM 6.5

Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the c…

CVE-2023-29542
CRITICAL 9.8

A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .downlo…

CVE-2023-32214
HIGH 7.5

Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating…

CVE-2023-32208
MEDIUM 5.3

Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113.

CVE-2023-29532
MEDIUM 5.5

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB s…

CVE-2023-29531
CRITICAL 9.8

An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug onl…

CVE-2023-33133
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2023-33131
HIGH 8.8

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2023-32029
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2023-34114
HIGH 7.4

Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable infor…

CVE-2023-3217
HIGH 8.8

Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2023-3216
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2023-3215
HIGH 8.8

Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch…

CVE-2023-3214
HIGH 8.8

Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

CVE-2023-28600
MEDIUM 5.2

Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files poten…

CVE-2023-28599
MEDIUM 4.3

Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi…

CVE-2023-32022
HIGH · éditeur

Windows Server Service Security Feature Bypass Vulnerability

CVE-2023-32021
HIGH · éditeur

Windows SMB Witness Service Security Feature Bypass Vulnerability

CVE-2023-32020
HIGH · éditeur

Windows DNS Spoofing Vulnerability

CVE-2023-32019
HIGH · éditeur

Windows Kernel Information Disclosure Vulnerability

CVE-2023-32018
HIGH · éditeur

Windows Hello Remote Code Execution Vulnerability

CVE-2023-32017
HIGH · éditeur

Microsoft PostScript Printer Driver Remote Code Execution Vulnerability

CVE-2023-32016
HIGH · éditeur

Windows Installer Information Disclosure Vulnerability

CVE-2023-32015
CRITICAL · éditeur

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVE-2023-32014
CRITICAL · éditeur

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVE-2023-32013
CRITICAL · éditeur

Windows Hyper-V Denial of Service Vulnerability

CVE-2023-32012
HIGH · éditeur

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2023-32011
HIGH · éditeur

Windows iSCSI Discovery Service Denial of Service Vulnerability

CVE-2023-32010
HIGH · éditeur

Windows Bus Filter Driver Elevation of Privilege Vulnerability

CVE-2023-32009
HIGH · éditeur

Windows Collaborative Translation Framework Elevation of Privilege Vulnerability

CVE-2023-32008
HIGH · éditeur

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

CVE-2023-29373
HIGH · éditeur

Microsoft ODBC Driver Remote Code Execution Vulnerability

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa