Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 753 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 372 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 753
Activement exploitées
372
Fenêtre de publication
1997-01-01 → 2026-09-17

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 753 entrées
CVE
CVE-2026-12009
HIGH 8.3

Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the r…

CVE-2026-12008
HIGH 8.3

Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially…

CVE-2026-12007
HIGH 8.8

Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromi…

CVE-2026-1220
HIGH 7.5

Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security …

CVE-2026-8863
HIGH 7.8

Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the bo…

CVE-2026-50508
MEDIUM 6.5

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-50507
MEDIUM 6.8

Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-49160
HIGH 7.5

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

CVE-2026-48583
HIGH 7.8

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-48578
HIGH 7.9

Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.

CVE-2026-48576
HIGH 7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48575
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48574
HIGH 7.8

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

CVE-2026-48573
HIGH 7.9

No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48570
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48568
HIGH 7.9

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-48566
MEDIUM 5.5

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-48563
HIGH 7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47656
HIGH 7.9

Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.

CVE-2026-47654
HIGH 7.5

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47653
HIGH 8.8

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47652
HIGH 8.2

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.

CVE-2026-47648
HIGH 7.0

Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.

CVE-2026-47293
HIGH 7.0

Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.

CVE-2026-47291
CRITICAL 9.8

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

CVE-2026-47289
HIGH 8.8

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVE-2026-47288
HIGH 7.1

Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.

CVE-2026-45658
HIGH 7.8

Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.

CVE-2026-45657
CRITICAL 9.8

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

CVE-2026-45656
HIGH 7.8

Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.

CVE-2026-45655
MEDIUM 5.3

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-45654
HIGH 7.9

Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVE-2026-45653
HIGH 7.0

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-45649
HIGH 7.1

Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.

CVE-2026-45648
HIGH 8.8

Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

CVE-2026-45642
LOW 3.9

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a…

CVE-2026-45641
HIGH 8.4

Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.

CVE-2026-45640
HIGH 7.0

Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-45639
HIGH 7.5

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-45638
HIGH 7.8

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-45637
HIGH 7.8

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVE-2026-45636
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-45635
HIGH 8.1

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a netw…

CVE-2026-45634
MEDIUM 5.5

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

CVE-2026-45608
MEDIUM 6.8

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

CVE-2026-45607
HIGH 8.4

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

CVE-2026-45606
MEDIUM 5.5

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

CVE-2026-45605
HIGH 7.8

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

CVE-2026-45604
MEDIUM 5.5

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

CVE-2026-45603
HIGH 7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authoriz…

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa