Vulnérabilités
Vulnérabilités des apps suivies
25 753 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 372 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 753
- Activement exploitées
- 372
- Fenêtre de publication
- 1997-01-01 → 2026-09-17
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-42978
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… |
|
CVE-2026-42977
HIGH 7.8
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elev… |
|
CVE-2026-42974
HIGH 8.1
Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-42973
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42972
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. |
|
CVE-2026-42971
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42970
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42969
MEDIUM 5.5
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42968
MEDIUM 5.5
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-42916
HIGH 7.8
Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42915
MEDIUM 5.5
Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally. |
|
CVE-2026-42914
MEDIUM 5.3
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. |
|
CVE-2026-42913
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute… |
|
CVE-2026-42912
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to eleva… |
|
CVE-2026-42911
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42910
HIGH 7.8
Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42909
HIGH 7.5
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute… |
|
CVE-2026-42908
HIGH 7.5
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
|
CVE-2026-42907
MEDIUM 6.5
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. |
|
CVE-2026-42906
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. |
|
CVE-2026-42905
HIGH 7.8
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42904
CRITICAL 9.6
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. |
|
CVE-2026-42903
MEDIUM 6.5
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. |
|
CVE-2026-42837
HIGH 7.8
Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-42836
HIGH 7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized atta… |
|
CVE-2026-42829
HIGH 7.8
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-42828
HIGH 7.8
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-41108
HIGH 7.0
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-41092
HIGH 7.8
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-40409
HIGH 7.8
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-40404
HIGH 7.8
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-34335
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33828
HIGH 7.8
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. |
|
CVE-2025-10263
CRITICAL 9.1
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C… |
|
CVE-2026-11701
Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (… |
|
CVE-2026-11700
Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a … |
|
CVE-2026-11699
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML… |
|
CVE-2026-11698
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML… |
|
CVE-2026-11697
Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via… |
|
CVE-2026-11696
Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain pot… |
|
CVE-2026-11695
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page.… |
|
CVE-2026-11694
Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to execute arbitrar… |
|
CVE-2026-11693
Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass s… |
|
CVE-2026-11692
Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perf… |
|
CVE-2026-11691
Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer … |
|
CVE-2026-11690
Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to exe… |
|
CVE-2026-11689
Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to byp… |
|
CVE-2026-11688
Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted… |
|
CVE-2026-11687
Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… |
|
CVE-2026-11686
Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer… |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.