Récap annuel
Sécurité des apps · 2024
Bilan 2024 indexé par Appaloosa Scout : 2 049 CVE publiées dans l'année sur les apps suivies, 45 ajoutées au catalogue CISA KEV (exploitées en réel), 8 apps affectées par au moins une KEV.
Voir les tendances pluriannuelles dans l'Observatoire des menaces
- CVE indexées dans l'année
- 2 049
- KEV CISA ajoutées
- 45
- Apps suivies touchées
- 8
Distribution par sévérité
CRITICAL
99
HIGH
1 408
MEDIUM
481
LOW
61
Top 10 KEV de l'année
Triées par sévérité CVSS. « Apps » compte les apps suivies du catalogue : beaucoup de KEV sont au niveau OS et affichent légitimement 0.
| CVE | Sévérité | Apps | Ajouté KEV | Description |
|---|---|---|---|---|
|
CVE-2024-9680
2 apps
|
CRITICAL 9.8 | 2 | 2024-10-15 | An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had re… |
|
CVE-2014-0497
2 apps
|
CRITICAL 9.8 | 2 | 2024-09-17 | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before … |
|
CVE-2024-4577
0 apps
|
CRITICAL 9.8 | 0 | 2024-06-12 | Argument Injection in PHP-CGI |
|
CVE-2024-21410
0 apps
|
CRITICAL 9.8 | 0 | 2024-02-15 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
|
CVE-2023-29357
0 apps
|
CRITICAL 9.8 | 0 | 2024-01-10 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
|
CVE-2024-7971
3 apps
|
CRITICAL 9.6 | 3 | 2024-08-26 | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. … |
|
CVE-2024-5274
2 apps
|
CRITICAL 9.6 | 2 | 2024-05-28 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr… |
|
CVE-2024-4947
2 apps
|
CRITICAL 9.6 | 2 | 2024-05-20 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a cra… |
|
CVE-2024-4671
2 apps
|
CRITICAL 9.6 | 2 | 2024-05-13 | Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to po… |
|
CVE-2024-7965
2 apps
|
HIGH 8.8 | 2 | 2024-08-28 | Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption… |
Top vendors par KEV cette année
- 1 Google LLC 10 KEV · 1 apps
- 2 Mozilla 1 KEV · 2 apps
- 3 Authy 1 KEV · 1 apps
- 4 Microsoft 1 KEV · 1 apps
- 5 Microsoft Corporation 1 KEV · 1 apps
- 6 Microsoft Office 1 KEV · 1 apps
Apps les plus affectées
Google Chrome
winget:Google.Chrome
Aucune vuln. ouverte
Chrome
com.google.Chrome
Aucune vuln. ouverte
Mozilla Thunderbird
winget:Mozilla.Thunderbird
Aucune vuln. ouverte
Mozilla Firefox
winget:Mozilla.Firefox
Aucune vuln. ouverte
Office
winget:Microsoft.Office
Aucune vuln. ouverte
Microsoft Edge
winget:Microsoft.Edge
Aucune vuln. ouverte
Twilio Authy Authenticator
com.authy.authy
Aucune vuln. ouverte
Microsoft Office
brew:cask:microsoft-office
Aucune vuln. ouverte
Méthodologie
KEV : ajoutées au catalogue CISA durant l'année (kev_added_date). CVE : date de publication NVD. Apps : celles indexées dans Scout au moment de la requête, l'historique évolue à chaque nouvel ajout au catalogue.