Skip to content
Appaloosa Scout
Language selector
fr en

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

294 actively exploited CVEs (High, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.

Matching CVEs
294
Actively exploited
294
Publication window
2007-02-03 → 2026-09-09

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

294 entries High Hide N/A CISA KEV Clear all
CVE
CVE-2022-3723
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

CVE-2022-41033
HIGH · vendor

Windows COM+ Event System Service Elevation of Privilege Vulnerability

CVE-2022-38028
HIGH · vendor

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-3038
HIGH 8.8

Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

CVE-2022-37969
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2022-34713
HIGH · vendor

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

CVE-2022-2294
HIGH 8.8

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

CVE-2022-1364
HIGH 8.8

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-1096
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-22047
HIGH · vendor

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

CVE-2022-30190
HIGH 7.8

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully e…

CVE-2022-26925
HIGH · vendor

Windows LSA Spoofing Vulnerability

CVE-2022-26904
HIGH · vendor

Windows User Profile Service Elevation of Privilege Vulnerability

CVE-2022-24521
HIGH · vendor

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2022-0609
HIGH 8.8

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-4102
HIGH 8.8

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-22718
HIGH · vendor

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-21999
HIGH · vendor

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-21971
HIGH · vendor

Windows Runtime Remote Code Execution Vulnerability

CVE-2022-21882
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2022-21919
HIGH · vendor

Windows User Profile Service Elevation of Privilege Vulnerability

CVE-2021-43226
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2021-38003
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

CVE-2021-42292
HIGH 7.8

Microsoft Excel Security Feature Bypass Vulnerability

CVE-2021-42287
HIGH 7.5

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2021-42278
HIGH 7.5

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2021-1048
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-0920
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-41357
HIGH · vendor

Win32k Elevation of Privilege Vulnerability

CVE-2021-40450
HIGH · vendor

Win32k Elevation of Privilege Vulnerability

CVE-2021-40449
HIGH · vendor

Win32k Elevation of Privilege Vulnerability

CVE-2021-37975
HIGH 8.8

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-30632
HIGH 8.8

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-40444
HIGH 8.8

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks th…

CVE-2021-38646
HIGH 7.8

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

CVE-2021-36955
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2021-36948
HIGH 7.8

Windows Update Medic Service Elevation of Privilege Vulnerability

CVE-2021-36942
HIGH 7.5

Windows LSA Spoofing Vulnerability

CVE-2021-34486
HIGH 7.8

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2021-34484
HIGH 7.8

Windows User Profile Service Elevation of Privilege Vulnerability

CVE-2021-30563
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-36934
HIGH 7.8

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accoun…

CVE-2021-33771
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2021-31979
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2021-34527
HIGH 8.8

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull…

CVE-2021-30554
HIGH 8.8

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-30551
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-1675
HIGH 7.8

Windows Print Spooler Remote Code Execution Vulnerability

CVE-2021-33739
HIGH · vendor

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2021-31956
HIGH · vendor

Windows NTFS Elevation of Privilege Vulnerability

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM