Vulnérabilités
Vulnérabilités des apps suivies
25 748 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 372 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 748
- Activement exploitées
- 372
- Fenêtre de publication
- 1997-01-01 → 2026-09-17
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-61368
MEDIUM 5.0
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally. |
|
CVE-2026-61367
HIGH 7.8
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61366
HIGH 7.0
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61365
HIGH 7.8
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61364
HIGH 7.8
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61363
HIGH 7.5
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-61361
HIGH 7.0
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally. |
|
CVE-2026-61360
MEDIUM 5.5
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. |
|
CVE-2026-61359
HIGH 7.8
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61358
HIGH 7.8
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate … |
|
CVE-2026-61357
HIGH 7.8
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61356
HIGH 7.8
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61355
HIGH 7.8
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61353
HIGH 7.8
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61352
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute… |
|
CVE-2026-61350
MEDIUM 4.6
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-61349
HIGH 7.8
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61348
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61347
MEDIUM 5.5
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-61346
HIGH 7.0
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-61345
MEDIUM 6.5
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. |
|
CVE-2026-59138
MEDIUM 6.5
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. |
|
CVE-2026-59137
MEDIUM 5.5
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-59136
MEDIUM 5.5
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. |
|
CVE-2026-59135
MEDIUM 5.5
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. |
|
CVE-2026-59134
HIGH 7.5
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-59132
HIGH 7.5
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-59131
MEDIUM 5.6
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. |
|
CVE-2026-59130
MEDIUM 5.6
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. |
|
CVE-2026-59128
MEDIUM 5.5
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. |
|
CVE-2026-59127
HIGH 7.8
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-59126
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to e… |
|
CVE-2026-59125
HIGH 7.0
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-59122
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-56179
HIGH 8.3
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. |
|
CVE-2026-56174
HIGH 7.8
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-54984
HIGH 7.8
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. |
|
CVE-2026-54113
HIGH 7.5
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. |
|
CVE-2026-50472
HIGH 7.0
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-49179
HIGH 8.8
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code… |
|
CVE-2026-42976
HIGH 7.8
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-6727
MEDIUM 5.9
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may … |
|
CVE-2026-6726
HIGH 7.9
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a cred… |
|
CVE-2026-49746
HIGH 7.1
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU… |
|
CVE-2026-65667
CRITICAL 10.0
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. |
|
CVE-2026-62918
HIGH 7.5
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-62896
CRITICAL 9.6
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. |
|
CVE-2026-65400
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, m… |
|
CVE-2026-19177
Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to… |
|
CVE-2026-19176
Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code in… |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.