Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

26 364 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
26 364
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-10-06

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

26 364 entrées
CVE
CVE-2022-3075
CRITICAL 9.6 KEV

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially…

CVE-2022-3071
HIGH 8.8

Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific U…

CVE-2022-3058
HIGH 8.8

Use after free in Sign-In Flow in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to …

CVE-2022-3057
MEDIUM 6.5

Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML p…

CVE-2022-3056
MEDIUM 6.5

Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass content security policy …

CVE-2022-3055
HIGH 8.8

Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to pot…

CVE-2022-3054
MEDIUM 6.5

Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a craf…

CVE-2022-3053
MEDIUM 4.3

Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted…

CVE-2022-3052
HIGH 8.8

Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in…

CVE-2022-3051
HIGH 8.8

Heap buffer overflow in Exosphere in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in spec…

CVE-2022-3050
HIGH 8.8

Heap buffer overflow in WebUI in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI inte…

CVE-2022-3049
HIGH 8.8

Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific…

CVE-2022-3048
MEDIUM 6.8

Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigat…

CVE-2022-3047
MEDIUM 6.5

Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious exten…

CVE-2022-3046
HIGH 8.8

Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to potentially …

CVE-2022-3045
HIGH 8.8

Insufficient validation of untrusted input in V8 in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a…

CVE-2022-3044
MEDIUM 6.5

Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to by…

CVE-2022-3043
HIGH 8.8

Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specifi…

CVE-2022-3042
HIGH 8.8

Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted …

CVE-2022-3041
HIGH 8.8

Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-3040
HIGH 8.8

Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-3039
HIGH 8.8

Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-3038
HIGH 8.8 KEV

Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

CVE-2022-2998
HIGH 8.8

Use after free in Browser Creation in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who had convinced a user to engage in a specific UI inter…

CVE-2022-2861
MEDIUM 6.5

Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extensi…

CVE-2022-2860
MEDIUM 6.5

Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafte…

CVE-2022-2859
HIGH 8.8

Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a user to engage in specific UI interactions…

CVE-2022-2858
HIGH 8.8

Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via specific UI intera…

CVE-2022-2857
HIGH 8.8

Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-2856
MEDIUM 6.5 KEV

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a …

CVE-2022-2855
HIGH 8.8

Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-2854
HIGH 8.8

Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-2853
HIGH 8.8

Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to pot…

CVE-2022-2852
HIGH 8.8

Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-27492
HIGH 7.8

An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file.

CVE-2022-36934
CRITICAL 9.8

An integer overflow in WhatsApp could result in remote code execution in an established video call.

CVE-2022-37969
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2022-38006
HIGH · éditeur

Windows Graphics Component Information Disclosure Vulnerability

CVE-2022-38005
HIGH · éditeur

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-38004
HIGH · éditeur

Windows Fax Service Remote Code Execution Vulnerability

CVE-2022-37959
HIGH · éditeur

Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability

CVE-2022-37958
CRITICAL · éditeur

SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability

CVE-2022-37957
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-37956
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-37955
HIGH · éditeur

Windows Group Policy Elevation of Privilege Vulnerability

CVE-2022-37954
HIGH · éditeur

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2022-35841
HIGH · éditeur

Windows Enterprise App Management Service Remote Code Execution Vulnerability

CVE-2022-35840
HIGH · éditeur

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVE-2022-35838
HIGH · éditeur

HTTP V3 Denial of Service Vulnerability

CVE-2022-35837
HIGH · éditeur

Windows Graphics Component Information Disclosure Vulnerability

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa