CISA KEV
Actively exploited vulnerabilities (CISA KEV)
294 actively exploited CVEs (High, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.
- Matching CVEs
- 294
- Actively exploited
- 294
- Publication window
- 2007-02-03 → 2026-09-09
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2022-3723
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… |
|
CVE-2022-41033
HIGH · vendor
Windows COM+ Event System Service Elevation of Privilege Vulnerability |
|
CVE-2022-38028
HIGH · vendor
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-3038
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p… |
|
CVE-2022-37969
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2022-34713
HIGH · vendor
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability |
|
CVE-2022-2294
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… |
|
CVE-2022-1364
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2022-1096
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2022-22047
HIGH · vendor
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability |
|
CVE-2022-30190
HIGH 7.8
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully e… |
|
CVE-2022-26925
HIGH · vendor
Windows LSA Spoofing Vulnerability |
|
CVE-2022-26904
HIGH · vendor
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2022-24521
HIGH · vendor
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2022-0609
Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-4102
Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2022-22718
HIGH · vendor
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-21999
HIGH · vendor
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-21971
HIGH · vendor
Windows Runtime Remote Code Execution Vulnerability |
|
CVE-2022-21882
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2022-21919
HIGH · vendor
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2021-43226
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2021-38003
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p… |
|
CVE-2021-42292
Microsoft Excel Security Feature Bypass Vulnerability |
|
CVE-2021-42287
HIGH 7.5
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-42278
HIGH 7.5
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-1048
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0920
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-41357
HIGH · vendor
Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-40450
HIGH · vendor
Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-40449
HIGH · vendor
Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-37975
Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-30632
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-40444
HIGH 8.8
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks th… |
|
CVE-2021-38646
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability |
|
CVE-2021-36955
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2021-36948
HIGH 7.8
Windows Update Medic Service Elevation of Privilege Vulnerability |
|
CVE-2021-36942
HIGH 7.5
Windows LSA Spoofing Vulnerability |
|
CVE-2021-34486
HIGH 7.8
Windows Event Tracing Elevation of Privilege Vulnerability |
|
CVE-2021-34484
HIGH 7.8
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2021-30563
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-36934
HIGH 7.8
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accoun… |
|
CVE-2021-33771
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2021-31979
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2021-34527
HIGH 8.8
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull… |
|
CVE-2021-30554
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-30551
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-1675
HIGH 7.8
Windows Print Spooler Remote Code Execution Vulnerability |
|
CVE-2021-33739
HIGH · vendor
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2021-31956
HIGH · vendor
Windows NTFS Elevation of Privilege Vulnerability |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.