Skip to content
Appaloosa Scout
Language selector
fr en

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

294 actively exploited CVEs (High, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.

Matching CVEs
294
Actively exploited
294
Publication window
2007-02-03 → 2026-09-09

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

294 entries High Hide N/A CISA KEV Clear all
CVE
CVE-2021-31955
HIGH · vendor

Windows Kernel Information Disclosure Vulnerability

CVE-2021-31201
HIGH · vendor

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVE-2021-31199
HIGH · vendor

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVE-2021-28664
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-28663
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-1905
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-21224
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

CVE-2021-21220
HIGH 8.8

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a…

CVE-2021-21206
HIGH 8.8

Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-28310
HIGH · vendor

Win32k Elevation of Privilege Vulnerability

CVE-2021-21193
HIGH 8.8

Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-27059
HIGH 7.6

Microsoft Office Remote Code Execution Vulnerability

CVE-2021-26411
HIGH 8.8

Internet Explorer Memory Corruption Vulnerability

CVE-2021-21166
HIGH 8.8

Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-1732
HIGH 7.8

Windows Win32k Elevation of Privilege Vulnerability

CVE-2021-21148
HIGH 8.8

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2020-11261
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2020-17087
HIGH · vendor

Windows Kernel Local Elevation of Privilege Vulnerability

CVE-2020-1464
HIGH · vendor

Windows Spoofing Vulnerability

CVE-2020-0986
HIGH · vendor

Windows Kernel Elevation of Privilege Vulnerability

CVE-2020-1054
HIGH 7.0

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who succe…

CVE-2020-6820
HIGH 8.1

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing thi…

CVE-2020-6819
HIGH 8.1

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abu…

CVE-2020-1027
HIGH · vendor

Windows Kernel Elevation of Privilege Vulnerability

CVE-2020-0787
HIGH 7.8

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows …

CVE-2019-17026
HIGH 8.8

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild a…

CVE-2020-0069
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2020-0041
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2020-0683
HIGH · vendor

Windows Installer Elevation of Privilege Vulnerability

CVE-2019-18426
HIGH 8.2

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and l…

CVE-2020-0638
HIGH 7.8

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first …

CVE-2020-0601
HIGH · vendor

Windows CryptoAPI Spoofing Vulnerability

CVE-2019-1458
HIGH 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privil…

CVE-2019-1405
HIGH 7.8

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP…

CVE-2019-1385
HIGH 7.8

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to sys…

CVE-2019-1388
HIGH · vendor

Windows Certificate Dialog Elevation of Privilege Vulnerability

CVE-2019-1322
HIGH · vendor

Microsoft Windows Elevation of Privilege Vulnerability

CVE-2019-1315
HIGH · vendor

Windows Error Reporting Manager Elevation of Privilege Vulnerability

CVE-2019-2215
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2019-1297
HIGH 8.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Rem…

CVE-2019-1253
HIGH · vendor

Windows Elevation of Privilege Vulnerability

CVE-2019-1215
HIGH · vendor

Windows Elevation of Privilege Vulnerability

CVE-2019-1214
HIGH · vendor

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2019-11707
HIGH 8.8

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware…

CVE-2019-1130
HIGH 7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privileg…

CVE-2019-1129
HIGH · vendor

Windows Elevation of Privilege Vulnerability

CVE-2019-0880
HIGH · vendor

Microsoft splwow64 Elevation of Privilege Vulnerability

CVE-2019-1069
HIGH 7.8

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited …

CVE-2019-1064
HIGH · vendor

Windows Elevation of Privilege Vulnerability

CVE-2019-0863
HIGH · vendor

Windows Error Reporting Elevation of Privilege Vulnerability

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM