CISA KEV
Actively exploited vulnerabilities (CISA KEV)
294 actively exploited CVEs (High, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.
- Matching CVEs
- 294
- Actively exploited
- 294
- Publication window
- 2007-02-03 → 2026-09-09
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-21338
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-23222
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS … |
|
CVE-2024-0519
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML … |
|
CVE-2023-41974
HIGH 7.8
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be … |
|
CVE-2023-7024
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… |
|
CVE-2023-33107
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33106
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33063
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-42917
HIGH 8.8
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2.… |
|
CVE-2023-36424
HIGH · vendor
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36036
HIGH · vendor
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36033
HIGH · vendor
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2023-36025
HIGH · vendor
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-44487
HIGH 7.5
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w… |
|
CVE-2023-36584
HIGH · vendor
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2023-36563
HIGH · vendor
Microsoft WordPad Information Disclosure Vulnerability |
|
CVE-2023-4211
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-5217
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap… |
|
CVE-2023-26369
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerabil… |
|
CVE-2023-4863
HIGH 8.8
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write v… |
|
CVE-2023-36802
HIGH · vendor
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability |
|
CVE-2023-4762
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security s… |
|
CVE-2023-35674
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-38831
HIGH 7.8
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because … |
|
CVE-2023-36884
HIGH 7.5
Windows Search Remote Code Execution Vulnerability |
|
CVE-2023-35311
Microsoft Outlook Security Feature Bypass Vulnerability |
|
CVE-2023-36874
HIGH · vendor
Windows Error Reporting Service Elevation of Privilege Vulnerability |
|
CVE-2023-32049
HIGH · vendor
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-32046
HIGH · vendor
Windows MSHTML Platform Elevation of Privilege Vulnerability |
|
CVE-2021-29256
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-29360
HIGH · vendor
Microsoft Streaming Service Elevation of Privilege Vulnerability |
|
CVE-2023-3079
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2022-22706
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-29336
HIGH · vendor
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-0266
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-0847
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-22600
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-2033
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2023-28252
HIGH · vendor
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-28229
HIGH · vendor
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |
|
CVE-2022-38181
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-20963
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-21823
HIGH 7.8
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2023-23376
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-21608
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerabil… |
|
CVE-2023-21674
HIGH · vendor
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability |
|
CVE-2022-4262
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… |
|
CVE-2022-41128
HIGH 8.8
Windows Scripting Languages Remote Code Execution Vulnerability |
|
CVE-2022-41125
HIGH 7.8
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |
|
CVE-2022-41073
HIGH 7.8
Windows Print Spooler Elevation of Privilege Vulnerability |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.