Skip to content
Appaloosa Scout
Language selector
fr en

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

54 actively exploited CVEs (all severities, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.

Matching CVEs
54
Actively exploited
286
Publication window
2010-10-28 → 2026-04-14

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

54 entries CISA KEV Public exploit Clear all
CVE
CVE-2026-32202
MEDIUM 4.3

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-59287
CRITICAL 9.8

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2025-33073
HIGH 8.8

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2025-30397
HIGH 7.5

Scripting Engine Memory Corruption Vulnerability

CVE-2025-26633
HIGH 7.0

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-24054
HIGH 6.5

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-24085
CRITICAL 10.0

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS…

CVE-2025-21333
HIGH 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2024-49138
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2024-38193
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2024-21338
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-44487
HIGH 7.5

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w…

CVE-2023-29336
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2022-0847
HIGH 7.8

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-44228
CRITICAL 10.0 1 app

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter…

CVE-2020-1472
CRITICAL 10.0

Netlogon Elevation of Privilege Vulnerability

CVE-2020-0796
CRITICAL 10.0

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S…

CVE-2019-17026
HIGH 8.8 1 app

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild a…

CVE-2020-0683
HIGH 7.0

Windows Installer Elevation of Privilege Vulnerability

CVE-2019-18426
HIGH 8.2 1 app

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and l…

CVE-2020-0601
HIGH 8.1

Windows CryptoAPI Spoofing Vulnerability

CVE-2019-1458
HIGH 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privil…

CVE-2019-1405
HIGH 7.8

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP…

CVE-2019-1322
HIGH 7.0

Microsoft Windows Elevation of Privilege Vulnerability

CVE-2019-2215
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2019-1253
HIGH 7.8

Windows Elevation of Privilege Vulnerability

CVE-2019-1215
HIGH 7.8

Windows Elevation of Privilege Vulnerability

CVE-2019-11708
CRITICAL 10.0 1 app

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op…

CVE-2019-11707
HIGH 8.8 1 app

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware…

CVE-2019-0863
HIGH 7.8

Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2019-0841
HIGH 6.8

Windows Elevation of Privilege Vulnerability

CVE-2019-0803
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2018-20250
HIGH 7.8 1 app

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When…

CVE-2019-0543
HIGH 7.8

Microsoft Windows Elevation of Privilege Vulnerability

CVE-2018-8453
HIGH 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privil…

CVE-2016-9079
HIGH 7.5 1 app

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a…

CVE-2018-8174
HIGH 7.5

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution …

CVE-2018-0824
HIGH 7.5

Microsoft COM for Windows Remote Code Execution Vulnerability

CVE-2017-8464
CRITICAL 7.5

LNK Remote Code Execution Vulnerability

CVE-2017-0263
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2017-0213
HIGH 6.7

Windows COM Elevation of Privilege Vulnerability

CVE-2017-0145
HIGH 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.…

CVE-2017-0144
HIGH 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.…

CVE-2017-0148
CRITICAL 8.1

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0147
HIGH 8.1

Windows SMB Information Disclosure Vulnerability

CVE-2017-0146
CRITICAL 8.1

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0143
CRITICAL 8.1

Windows SMB Remote Code Execution Vulnerability

CVE-2016-5195
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2016-7255
HIGH 6.1

Win32k Elevation of Privilege Vulnerability

CVE-2016-3309
HIGH

Windows Kernel Elevation of Privilege Vulnerability