Récap annuel
Sécurité des apps · 2025
Bilan 2025 indexé par Appaloosa Scout : 2 485 CVE publiées dans l'année sur les apps suivies, 64 ajoutées au catalogue CISA KEV (exploitées en réel), 7 apps affectées par au moins une KEV.
Voir les tendances pluriannuelles dans l'Observatoire des menaces
- CVE indexées dans l'année
- 2 485
- KEV CISA ajoutées
- 64
- Apps suivies touchées
- 7
Distribution par sévérité
CRITICAL
220
HIGH
1 656
MEDIUM
557
LOW
52
Top 10 KEV de l'année
Triées par sévérité CVSS. « Apps » compte les apps suivies du catalogue : beaucoup de KEV sont au niveau OS et affichent légitimement 0.
| CVE | Sévérité | Apps | Ajouté KEV | Description |
|---|---|---|---|---|
|
CVE-2025-43300
0 apps
|
CRITICAL 10.0 | 0 | 2025-08-21 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 … |
|
CVE-2025-32433
0 apps
|
CRITICAL 10.0 | 0 | 2025-06-09 | Erlang/OTP SSH Vulnerable to Pre-Authentication RCE |
|
CVE-2025-24201
0 apps
|
CRITICAL 10.0 | 0 | 2025-03-13 | An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS … |
|
CVE-2025-24085
0 apps
|
CRITICAL 10.0 | 0 | 2025-01-29 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS… |
|
CVE-2010-3765
2 apps
|
CRITICAL 9.8 | 2 | 2025-10-06 | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x be… |
|
CVE-2025-10585
2 apps
|
CRITICAL 9.8 | 2 | 2025-09-23 | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafte… |
|
CVE-2024-21413
2 apps
|
CRITICAL 9.8 | 2 | 2025-02-06 | Microsoft Outlook Remote Code Execution Vulnerability |
|
CVE-2025-14611
0 apps
|
CRITICAL 9.8 | 0 | 2025-12-15 | Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme.… |
|
CVE-2025-59287
0 apps
|
CRITICAL 9.8 | 0 | 2025-10-24 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
|
CVE-2025-53770
0 apps
|
CRITICAL 9.8 | 0 | 2025-07-20 | Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network… |
Top vendors par KEV cette année
- 1 Google LLC 7 KEV · 1 apps
- 2 Microsoft 2 KEV · 1 apps
- 3 Microsoft Office 2 KEV · 1 apps
- 4 win.rar GmbH 2 KEV · 1 apps
- 5 Microsoft Corporation 1 KEV · 4 apps
- 6 Mozilla 1 KEV · 2 apps
- 7 Apple Distribution International 1 KEV · 1 apps
- 8 Igor Pavlov 1 KEV · 1 apps
- 9 WhatsApp Inc. 1 KEV · 1 apps
Apps les plus affectées
Google Chrome
winget:Google.Chrome
Aucune vuln. ouverte
Chrome
com.google.Chrome
Aucune vuln. ouverte
WinRAR
winget:RARLab.WinRAR
Aucune vuln. ouverte
Office
winget:Microsoft.Office
Aucune vuln. ouverte
Safari
com.apple.Safari
Aucune vuln. ouverte
Microsoft Office
brew:cask:microsoft-office
Aucune vuln. ouverte
Mozilla Thunderbird
winget:Mozilla.Thunderbird
Aucune vuln. ouverte
Mozilla Firefox
winget:Mozilla.Firefox
Aucune vuln. ouverte
7-Zip
winget:7zip.7zip
Aucune vuln. ouverte
WhatsApp
ios:net.whatsapp.WhatsApp
Aucune vuln. ouverte
Méthodologie
KEV : ajoutées au catalogue CISA durant l'année (kev_added_date). CVE : date de publication NVD. Apps : celles indexées dans Scout au moment de la requête, l'historique évolue à chaque nouvel ajout au catalogue.