Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

KEV CISA

Vulnérabilités activement exploitées (KEV CISA)

372 CVE activement exploitées (toutes sévérités, toutes plateformes) touchent une app ou un OS suivi. La CISA confirme leur exploitation pour chacune.

CVE correspondantes
372
Activement exploitées
372
Fenêtre de publication
2007-02-03 → 2026-09-09

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

372 entrées KEV CISA Tout effacer
CVE
CVE-2026-87491
HIGH 8.8

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pag…

CVE-2026-85880
HIGH · éditeur

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

CVE-2026-81963
HIGH · éditeur

Windows Update Stack Elevation of Privilege Vulnerability

CVE-2026-85046
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C…

CVE-2026-68820
HIGH 7.0

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-65400
CRITICAL 9.8

An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, m…

CVE-2026-56155
HIGH 7.8

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVE-2026-11645
HIGH 8.8

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

CVE-2025-48595
HIGH 8.4

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no a…

CVE-2026-33824
CRITICAL 9.8

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

CVE-2026-32202
MEDIUM 4.3

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-34621
HIGH 8.6

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype…

CVE-2026-5281
HIGH 8.8

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code vi…

CVE-2026-3910
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

CVE-2026-3909
HIGH 8.8

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (…

CVE-2026-21385
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2026-2441
HIGH 8.8

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…

CVE-2026-20700
HIGH 7.8

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS …

CVE-2026-21533
HIGH · éditeur

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-21525
MEDIUM · éditeur

Windows Remote Access Connection Manager Denial of Service Vulnerability

CVE-2026-21519
HIGH · éditeur

Desktop Window Manager Elevation of Privilege Vulnerability

CVE-2026-21513
HIGH · éditeur

MSHTML Framework Security Feature Bypass Vulnerability

CVE-2026-21510
HIGH · éditeur

Windows Shell Security Feature Bypass Vulnerability

CVE-2026-21509
HIGH 7.8

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-20805
MEDIUM 5.5

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

CVE-2025-43529
HIGH 8.8

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.…

CVE-2025-43520
MEDIUM 5.5

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Seq…

CVE-2025-43510
HIGH 7.8

A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS…

CVE-2025-14174
HIGH 8.8

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a cra…

CVE-2025-62221
HIGH · éditeur

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-48633
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-48572
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-13223
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2025-62215
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-60710
HIGH · éditeur

Host Process for Windows Tasks Elevation of Privilege Vulnerability

CVE-2023-43000
HIGH 8.8

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.…

CVE-2025-59287
CRITICAL · éditeur

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2025-59230
HIGH · éditeur

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-47827
HIGH · éditeur

MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11

CVE-2025-24990
HIGH · éditeur

Windows Agere Modem Driver Elevation of Privilege Vulnerability

CVE-2025-10585
CRITICAL 9.8

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2025-39682
CRITICAL 9.8

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process …

CVE-2025-48543
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-55177
MEDIUM 5.4

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsAp…

CVE-2025-43300
CRITICAL 10.0

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, …

CVE-2025-8088
HIGH 8.8

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This…

CVE-2025-27038
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-21479
CRITICAL · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-31277
HIGH 8.8

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.…

CVE-2025-38352
HIGH 7.8

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If…