KEV CISA
Vulnérabilités activement exploitées (KEV CISA)
31 CVE activement exploitées (Modéré, toutes plateformes) touchent une app ou un OS suivi. La CISA confirme leur exploitation pour chacune.
- CVE correspondantes
- 31
- Activement exploitées
- 31
- Fenêtre de publication
- 2013-05-16 → 2026-04-14
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-32202
MEDIUM 4.3
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-21525
MEDIUM · éditeur
Windows Remote Access Connection Manager Denial of Service Vulnerability |
|
CVE-2026-20805
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. |
|
CVE-2025-43520
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Seq… |
|
CVE-2025-55177
MEDIUM 5.4
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsAp… |
|
CVE-2025-43200
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.… |
|
CVE-2024-50302
MEDIUM · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-24200
MEDIUM 6.1
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 1… |
|
CVE-2024-44309
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPad… |
|
CVE-2024-43573
MEDIUM · éditeur
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-38217
MEDIUM 5.4
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-38213
MEDIUM · éditeur
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-39891
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-numb… |
|
CVE-2023-42916
MEDIUM 6.5
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Pr… |
|
CVE-2023-36761
Microsoft Word Information Disclosure Vulnerability |
|
CVE-2023-26083
MEDIUM · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-24880
MEDIUM · éditeur
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-44698
MEDIUM · éditeur
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-41091
MEDIUM 5.4
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2022-41049
MEDIUM 5.4
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2022-2856
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a … |
|
CVE-2013-3900
MEDIUM · éditeur
WinVerifyTrust Signature Validation Vulnerability |
|
CVE-2021-38000
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a m… |
|
CVE-2021-41379
MEDIUM 5.5
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2021-37976
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from proces… |
|
CVE-2021-34448
MEDIUM 6.8
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-30533
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafte… |
|
CVE-2021-1906
MEDIUM · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2020-0878
MEDIUM 4.2
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way th… |
|
CVE-2016-3351
MEDIUM 6.5
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Brows… |
|
CVE-2013-1675
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data … |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.