Skip to content
Appaloosa Scout
Language selector
fr en

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

294 actively exploited CVEs (High, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.

Matching CVEs
294
Actively exploited
294
Publication window
2007-02-03 → 2026-09-09

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

294 entries High Hide N/A CISA KEV Clear all
CVE
CVE-2024-21338
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-23222
HIGH 8.8

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS …

CVE-2024-0519
HIGH 8.8

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

CVE-2023-41974
HIGH 7.8

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be …

CVE-2023-7024
HIGH 8.8

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

CVE-2023-33107
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-33106
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-33063
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-42917
HIGH 8.8

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2.…

CVE-2023-36424
HIGH · vendor

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-36036
HIGH · vendor

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-36033
HIGH · vendor

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2023-36025
HIGH · vendor

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2023-44487
HIGH 7.5

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w…

CVE-2023-36584
HIGH · vendor

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2023-36563
HIGH · vendor

Microsoft WordPad Information Disclosure Vulnerability

CVE-2023-4211
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-5217
HIGH 8.8

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap…

CVE-2023-26369
HIGH 7.8

Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerabil…

CVE-2023-4863
HIGH 8.8

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write v…

CVE-2023-36802
HIGH · vendor

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CVE-2023-4762
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security s…

CVE-2023-35674
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-38831
HIGH 7.8

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because …

CVE-2023-36884
HIGH 7.5

Windows Search Remote Code Execution Vulnerability

CVE-2023-35311
HIGH 8.8

Microsoft Outlook Security Feature Bypass Vulnerability

CVE-2023-36874
HIGH · vendor

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2023-32049
HIGH · vendor

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2023-32046
HIGH · vendor

Windows MSHTML Platform Elevation of Privilege Vulnerability

CVE-2021-29256
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-29360
HIGH · vendor

Microsoft Streaming Service Elevation of Privilege Vulnerability

CVE-2023-3079
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2022-22706
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-29336
HIGH · vendor

Win32k Elevation of Privilege Vulnerability

CVE-2023-0266
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2022-0847
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-22600
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-2033
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2023-28252
HIGH · vendor

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-28229
HIGH · vendor

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVE-2022-38181
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-20963
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-21823
HIGH 7.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2023-23376
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-21608
HIGH 7.8

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerabil…

CVE-2023-21674
HIGH · vendor

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

CVE-2022-4262
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

CVE-2022-41128
HIGH 8.8

Windows Scripting Languages Remote Code Execution Vulnerability

CVE-2022-41125
HIGH 7.8

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVE-2022-41073
HIGH 7.8

Windows Print Spooler Elevation of Privilege Vulnerability

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM