Vulnérabilités
Vulnérabilités des apps suivies
26 363 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 26 363
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-10-06
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-20755
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-20754
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-42703
MEDIUM · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-28350
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-29256
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-0948
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-36539
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. |
|
CVE-2023-34658
MEDIUM 5.3
Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController. |
|
CVE-2023-3422
Use after free in Guest View in Google Chrome prior to 114.0.5735.198 allowed an attacker who convinced a user to install a malicious extension to potentially … |
|
CVE-2023-3421
Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
|
CVE-2023-3420
Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2023-36632
The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling … |
|
CVE-2023-32395
MEDIUM 5.5
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may … |
|
CVE-2023-32353
HIGH 7.8
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to elevate privileges. |
|
CVE-2023-32351
HIGH 7.8
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to gain elevated privileges. |
|
CVE-2023-34417
CRITICAL 9.8
Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h… |
|
CVE-2023-34416
Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume t… |
|
CVE-2023-34414
The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks tha… |
|
CVE-2023-29545
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the c… |
|
CVE-2023-29542
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .downlo… |
|
CVE-2023-32214
Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating… |
|
CVE-2023-32208
MEDIUM 5.3
Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113. |
|
CVE-2023-29532
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB s… |
|
CVE-2023-29531
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug onl… |
|
CVE-2023-33133
Microsoft Excel Remote Code Execution Vulnerability |
|
CVE-2023-33131
Microsoft Outlook Remote Code Execution Vulnerability |
|
CVE-2023-32029
Microsoft Excel Remote Code Execution Vulnerability |
|
CVE-2023-34114
HIGH 7.4
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable infor… |
|
CVE-2023-3217
Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
|
CVE-2023-3216
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2023-3215
Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch… |
|
CVE-2023-3214
Use after free in Autofill payments in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM… |
|
CVE-2023-28600
MEDIUM 5.2
Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files poten… |
|
CVE-2023-28599
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi… |
|
CVE-2023-32022
HIGH · éditeur
Windows Server Service Security Feature Bypass Vulnerability |
|
CVE-2023-32021
HIGH · éditeur
Windows SMB Witness Service Security Feature Bypass Vulnerability |
|
CVE-2023-32020
HIGH · éditeur
Windows DNS Spoofing Vulnerability |
|
CVE-2023-32019
HIGH · éditeur
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2023-32018
HIGH · éditeur
Windows Hello Remote Code Execution Vulnerability |
|
CVE-2023-32017
HIGH · éditeur
Microsoft PostScript Printer Driver Remote Code Execution Vulnerability |
|
CVE-2023-32016
HIGH · éditeur
Windows Installer Information Disclosure Vulnerability |
|
CVE-2023-32015
CRITICAL · éditeur
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2023-32014
CRITICAL · éditeur
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2023-32013
CRITICAL · éditeur
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2023-32012
HIGH · éditeur
Windows Container Manager Service Elevation of Privilege Vulnerability |
|
CVE-2023-32011
HIGH · éditeur
Windows iSCSI Discovery Service Denial of Service Vulnerability |
|
CVE-2023-32010
HIGH · éditeur
Windows Bus Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-32009
HIGH · éditeur
Windows Collaborative Translation Framework Elevation of Privilege Vulnerability |
|
CVE-2023-32008
HIGH · éditeur
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability |
|
CVE-2023-29373
HIGH · éditeur
Microsoft ODBC Driver Remote Code Execution Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.