Vulnérabilités
Aggrégat CVE / GHSA / KEV / OSV — filtrage par étiquette et catégorie.
| ID | Titre | |
|---|---|---|
| CVE-2026-69665 |
|
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
|
| CVE-2026-68062 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-64878 |
|
Injection de commande OS dans tenable (CVE-2026-64878)
injection de commande OS dans tenable (CVE-2026-64878). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2026-8505 |
|
Vulnérabilité dans langflow (CVE-2026-8505)
vulnérabilité dans langflow (CVE-2026-8505). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2026-8481 |
|
Injection de code dans c (CVE-2026-8481)
injection de code dans c (CVE-2026-8481). L'exploitation peut entraîner la prise de contrôle totale du système. Exploitable via `POST /api/v1/validate/code`.
|
| CVE-2026-8476 |
|
Désérialisation non sécurisée dans langflow (CVE-2026-8476)
vulnérabilité dans langflow (CVE-2026-8476). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2026-8056 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
|
| CVE-2026-7755 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
|
| CVE-2026-7667 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
|
| CVE-2026-13448 |
|
Vulnérabilité dans langflow (CVE-2026-13448)
vulnérabilité dans langflow (CVE-2026-13448). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2026-45313 |
|
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and...
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER request without validating that the thread belongs to the...
|
| CVE-2026-47908 |
|
Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer...
Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer...
|
| CVE-2026-47907 |
|
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control...
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control...
|
| CVE-2026-47906 |
|
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third...
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third...
|
| CVE-2026-8855 |
|
Injection de code dans dos (CVE-2026-8855)
injection de code dans dos (CVE-2026-8855). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2026-43941 |
|
Vulnérabilité dans electerm (CVE-2026-43941)
vulnérabilité dans electerm (CVE-2026-43941). L'exploitation peut entraîner la prise de contrôle totale du système. Exploitable via ``shell.openExternal``.
|
| CVE-2026-43208 |
|
Vulnérabilité dans linux (CVE-2026-43208)
vulnérabilité dans linux (CVE-2026-43208). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2026-43205 |
|
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: validate...
In the Linux kernel, the following vulnerability has been resolved:
dpaa2-switch: validate...
|
| CVE-2026-43197 |
|
Vulnérabilité dans linux (CVE-2026-43197)
vulnérabilité dans linux (CVE-2026-43197). Des informations confidentielles peuvent être exposées.
|
| CVE-2026-43185 |
|
Vulnérabilité dans linux (CVE-2026-43185)
vulnérabilité dans linux (CVE-2026-43185). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2026-43125 |
|
Écriture hors limites dans linux (CVE-2026-43125)
écriture hors limites dans linux (CVE-2026-43125). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2026-43067 |
|
Vulnérabilité dans linux (CVE-2026-43067)
vulnérabilité dans linux (CVE-2026-43067). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2026-26956 |
|
Vulnérabilité dans vm2-project (CVE-2026-26956)
vulnérabilité dans vm2-project (CVE-2026-26956). L'exploitation peut entraîner la prise de contrôle totale du système. Exploitable via ``catch``.
|
| CVE-2026-43038 |
|
Vulnérabilité dans linux (CVE-2026-43038)
vulnérabilité dans linux (CVE-2026-43038). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2026-42249 |
|
Traversée de chemin dans path-traversal (CVE-2026-42249)
traversée de chemin dans path-traversal (CVE-2026-42249). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2026-7355 |
|
Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
|
| CVE-2026-7356 |
|
Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7358 |
|
Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7348 |
|
Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7336 |
|
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7335 |
|
Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2009-0238 KEV |
|
[KEV] Injection de code dans Microsoft office (CVE-2009-0238)
injection de code dans Microsoft office (CVE-2009-0238). Risque d'opérations non autorisées ou de divulgation. Inscrit au CISA KEV — exploitation active confirmée.
|
| CVE-2026-34621 KEV |
|
[KEV] Vulnérabilité dans Adobe acrobat-and-reader (CVE-2026-34621)
vulnérabilité dans Adobe acrobat-and-reader (CVE-2026-34621). Risque d'opérations non autorisées ou de divulgation. Inscrit au CISA KEV — exploitation active confirmée.
|
| CVE-2026-3843 |
|
Injection SQL dans sqli (CVE-2026-3843)
injection SQL dans sqli (CVE-2026-3843). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2023-6377 |
|
Lecture hors limites dans privilege-escalation (CVE-2023-6377)
vulnérabilité dans privilege-escalation (CVE-2023-6377). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2023-36884 KEV |
|
[KEV] Vulnérabilité dans Microsoft windows (CVE-2023-36884)
vulnérabilité dans Microsoft windows (CVE-2023-36884). L'exploitation peut entraîner la prise de contrôle totale du système. Inscrit au CISA KEV — exploitation active confirmée.
|
| CVE-2016-8735 KEV |
|
[KEV] Vulnérabilité dans Apache tomcat (CVE-2016-8735)
vulnérabilité dans Apache tomcat (CVE-2016-8735). L'exploitation peut entraîner la prise de contrôle totale du système. Inscrit au CISA KEV — exploitation active confirmée.
|
| CVE-2023-21823 KEV |
|
[KEV] Vulnérabilité dans Microsoft windows (CVE-2023-21823)
vulnérabilité dans Microsoft windows (CVE-2023-21823). L'exploitation peut entraîner la prise de contrôle totale du système. Inscrit au CISA KEV — exploitation active confirmée.
|
| CVE-2023-25136 |
|
Vulnérabilité dans openbsd (CVE-2023-25136)
vulnérabilité dans openbsd (CVE-2023-25136). Risque d'opérations non autorisées ou de divulgation.
|
| CVE-2022-41128 KEV |
|
[KEV] Écriture hors limites dans Microsoft windows (CVE-2022-41128)
écriture hors limites dans Microsoft windows (CVE-2022-41128). L'exploitation peut entraîner la prise de contrôle totale du système. Inscrit au CISA KEV — exploitation active confirmée.
|
| CVE-2022-36534 |
|
Injection de commande dans syncovery (CVE-2022-36534)
injection de commande dans syncovery (CVE-2022-36534). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2022-30190 KEV |
|
[KEV] Vulnérabilité dans Microsoft windows (CVE-2022-30190)
vulnérabilité dans Microsoft windows (CVE-2022-30190). L'exploitation peut entraîner la prise de contrôle totale du système. Inscrit au CISA KEV — exploitation active confirmée.
|
| CVE-2022-28944 |
|
Vulnérabilité dans emcosoftware (CVE-2022-28944)
vulnérabilité dans emcosoftware (CVE-2022-28944). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2018-7602 KEV |
|
[KEV] Injection de code dans Drupal core (CVE-2018-7602)
injection de code dans Drupal core (CVE-2018-7602). L'exploitation peut entraîner la prise de contrôle totale du système. Inscrit au CISA KEV — exploitation active confirmée.
|
| CVE-2022-24512 |
|
Injection de code dans Microsoft.NETCore.App.Runtime.linux-arm (CVE-2022-24512)
injection de code dans Microsoft.NETCore.App.Runtime.linux-arm (CVE-2022-24512). Risque d'opérations non autorisées ou de divulgation. Atténuation : mise à jour vers `6.0.3` ou plus.
|
| CVE-2020-1938 KEV |
|
[KEV] Élévation de privilèges dans org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938)
vulnérabilité dans org.apache.tomcat.embed:tomcat-embed-core (CVE-2020-1938). L'exploitation peut entraîner la prise de contrôle totale du système. Inscrit au CISA KEV — exploitation active confirmée. Atténuation : mise à jour vers `7.0.100` ou plus.
|
| CVE-2018-8174 KEV |
|
[KEV] Écriture hors limites dans Microsoft windows (CVE-2018-8174)
écriture hors limites dans Microsoft windows (CVE-2018-8174). L'exploitation peut entraîner la prise de contrôle totale du système. Inscrit au CISA KEV — exploitation active confirmée.
|
| CVE-2021-42638 |
|
Injection de commande dans printerlogic (CVE-2021-42638)
injection de commande dans printerlogic (CVE-2021-42638). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2021-42631 |
|
Désérialisation non sécurisée dans printerlogic (CVE-2021-42631)
vulnérabilité dans printerlogic (CVE-2021-42631). L'exploitation peut entraîner la prise de contrôle totale du système.
|
| CVE-2021-42635 |
|
Vulnérabilité dans printerlogic (CVE-2021-42635)
vulnérabilité dans printerlogic (CVE-2021-42635). L'exploitation peut entraîner la prise de contrôle totale du système.
|