Skip to content
Appaloosa Scout
Language selector
fr en

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

12 actively exploited CVEs (Critical, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.

Matching CVEs
12
Actively exploited
33
Publication window
2010-10-28 → 2025-10-14

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

12 entries Critical CISA KEV Public exploit Clear all
CVE
CVE-2025-59287
CRITICAL 9.8

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2025-24085
CRITICAL 10.0

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS…

CVE-2021-44228
CRITICAL 10.0 1 app

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter…

CVE-2020-1472
CRITICAL 10.0

Netlogon Elevation of Privilege Vulnerability

CVE-2020-0796
CRITICAL 10.0

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S…

CVE-2019-11708
CRITICAL 10.0 1 app

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op…

CVE-2017-8464
CRITICAL 7.5

LNK Remote Code Execution Vulnerability

CVE-2017-0148
CRITICAL 8.1

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0146
CRITICAL 8.1

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0143
CRITICAL 8.1

Windows SMB Remote Code Execution Vulnerability

CVE-2016-5195
CRITICAL

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2010-3765
CRITICAL 9.8 1 app

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when Ja…