CISA KEV
Actively exploited vulnerabilities (CISA KEV)
294 actively exploited CVEs (High, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.
- Matching CVEs
- 294
- Actively exploited
- 294
- Publication window
- 2007-02-03 → 2026-09-09
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-27363
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-29824
HIGH · vendor
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-53197
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-53150
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-2783
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandb… |
|
CVE-2025-26633
HIGH 7.0
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-24993
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2025-24991
HIGH · vendor
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24985
HIGH · vendor
Windows Fast FAT File System Driver Remote Code Execution Vulnerability |
|
CVE-2025-24984
HIGH · vendor
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24983
HIGH · vendor
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-24054
HIGH · vendor
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2024-43093
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-21391
HIGH 7.1
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2025-21418
HIGH · vendor
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2024-53104
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-0411
HIGH 7.0
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installat… |
|
CVE-2025-21335
HIGH 7.8
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2025-21334
HIGH · vendor
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2025-21333
HIGH · vendor
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2024-49138
HIGH · vendor
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-44308
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 1… |
|
CVE-2024-49039
HIGH 8.8
Windows Task Scheduler Elevation of Privilege Vulnerability |
|
CVE-2024-43451
HIGH · vendor
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2024-43047
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43572
HIGH · vendor
Microsoft Management Console Remote Code Execution Vulnerability |
|
CVE-2024-43461
HIGH 8.8
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-38226
Microsoft Publisher Security Feature Bypass Vulnerability |
|
CVE-2024-38014
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2024-32896
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-7965
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML … |
|
CVE-2024-38193
HIGH · vendor
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2024-38178
HIGH · vendor
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2024-38107
HIGH · vendor
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability |
|
CVE-2024-38106
HIGH · vendor
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-36971
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-38112
HIGH · vendor
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-38080
HIGH · vendor
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2024-4610
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-35250
HIGH 7.8
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
|
CVE-2024-30088
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-4761
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. … |
|
CVE-2024-30051
HIGH · vendor
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2024-30040
HIGH · vendor
Windows MSHTML Platform Security Feature Bypass Vulnerability |
|
CVE-2024-29988
HIGH · vendor
SmartScreen Prompt Security Feature Bypass Vulnerability |
|
CVE-2024-26169
HIGH · vendor
Windows Error Reporting Service Elevation of Privilege Vulnerability |
|
CVE-2024-23296
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey… |
|
CVE-2024-23225
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey… |
|
CVE-2024-21412
HIGH 8.1
Internet Shortcut Files Security Feature Bypass Vulnerability |
|
CVE-2024-21351
HIGH 7.6
Windows SmartScreen Security Feature Bypass Vulnerability |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.