Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

26 374 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
26 374
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-10-06

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

26 374 entrées
CVE
CVE-2021-41379
MEDIUM 5.5 KEV

Windows Installer Elevation of Privilege Vulnerability

CVE-2021-41378
HIGH 7.8

Windows NTFS Remote Code Execution Vulnerability

CVE-2021-41377
HIGH 7.8

Windows Fast FAT File System Driver Elevation of Privilege Vulnerability

CVE-2021-41371
MEDIUM 4.4

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

CVE-2021-41370
HIGH 7.8

NTFS Elevation of Privilege Vulnerability

CVE-2021-41368
MEDIUM 6.1

Microsoft Access Remote Code Execution Vulnerability

CVE-2021-41367
HIGH 7.8

NTFS Elevation of Privilege Vulnerability

CVE-2021-41366
HIGH 7.8

Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability

CVE-2021-41356
HIGH 7.5

Windows Denial of Service Vulnerability

CVE-2021-41351
MEDIUM 4.3

Microsoft Edge (Chrome based) Spoofing on IE Mode

CVE-2021-40442
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2021-38666
HIGH 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2021-38665
HIGH 7.4

Remote Desktop Protocol Client Information Disclosure Vulnerability

CVE-2021-38631
MEDIUM 4.4

Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability

CVE-2021-36957
HIGH 7.8

Windows Desktop Bridge Elevation of Privilege Vulnerability

CVE-2021-26443
CRITICAL 9.0

Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability

CVE-2021-38502
MEDIUM 5.9

Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted mes…

CVE-2021-38501
HIGH 8.8

Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presu…

CVE-2021-38500
HIGH 8.8

Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presu…

CVE-2021-38498
HIGH 7.5

During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitabl…

CVE-2021-38497
MEDIUM 6.5

Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusi…

CVE-2021-38496
HIGH 8.8

During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable cras…

CVE-2021-38495
HIGH 8.8

Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs showed evidence of memory corruption and we presume that with…

CVE-2021-38493
HIGH 8.8

Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we pres…

CVE-2021-38492
MEDIUM 6.5

When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in In…

CVE-2021-29991
HIGH 8.1

Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers…

CVE-2020-6492
CRITICAL 9.6

Use after free in ANGLE in Google Chrome prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVE-2018-6125
MEDIUM 6.5

Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information …

CVE-2018-6122
HIGH 8.8

Type confusion in WebAssembly in Google Chrome prior to 66.0.3359.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-37996
MEDIUM 5.5

Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a m…

CVE-2021-37995
MEDIUM 6.5

Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially overlay and spoof the contents…

CVE-2021-37994
MEDIUM 6.5

Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypass navigation restrictions via a crafted…

CVE-2021-37993
HIGH 8.8

Use after free in PDF Accessibility in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

CVE-2021-37992
HIGH 8.8

Out of bounds read in WebAudio in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-37991
HIGH 7.5

Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-37990
MEDIUM 5.5

Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to leak cross-origin data via a crafted app.

CVE-2021-37989
MEDIUM 6.5

Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content security policy via a crafted HTML page.

CVE-2021-37988
HIGH 8.8

Use after free in Profiles in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who convinced a user to engage in specific gestures to potentially …

CVE-2021-37987
HIGH 8.8

Use after free in Network APIs in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-37986
HIGH 8.8

Heap buffer overflow in Settings in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to engage with Dev Tools to potentially exploit heap corrupti…

CVE-2021-37985
HIGH 8.8

Use after free in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had convinced a user to allow for connection to debugger to potential…

CVE-2021-37984
HIGH 8.8

Heap buffer overflow in PDFium in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-37983
HIGH 8.8

Use after free in Dev Tools in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-37982
HIGH 8.8

Use after free in Incognito in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-37981
CRITICAL 9.6

Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the renderer process to potentially perform a…

CVE-2021-37980
HIGH 7.4

Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.

CVE-2021-37979
HIGH 8.8

heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a malicious website to potent…

CVE-2021-37978
HIGH 8.8

Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-37977
HIGH 8.8

Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…

CVE-2021-30284
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa