Skip to content
Appaloosa Scout
Language selector
fr en

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

294 actively exploited CVEs (High, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.

Matching CVEs
294
Actively exploited
294
Publication window
2007-02-03 → 2026-09-09

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

294 entries High Hide N/A CISA KEV Clear all
CVE
CVE-2019-0859
HIGH · vendor

Win32k Elevation of Privilege Vulnerability

CVE-2019-0841
HIGH · vendor

Windows Elevation of Privilege Vulnerability

CVE-2019-0803
HIGH · vendor

Win32k Elevation of Privilege Vulnerability

CVE-2019-0797
HIGH · vendor

Win32k Elevation of Privilege Vulnerability

CVE-2019-0703
HIGH · vendor

Windows SMB Information Disclosure Vulnerability

CVE-2018-20250
HIGH 7.8

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When…

CVE-2019-0543
HIGH · vendor

Microsoft Windows Elevation of Privilege Vulnerability

CVE-2018-8639
HIGH · vendor

Win32k Elevation of Privilege Vulnerability

CVE-2018-8611
HIGH · vendor

Windows Kernel Elevation of Privilege Vulnerability

CVE-2018-8453
HIGH 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privil…

CVE-2018-8440
HIGH · vendor

Windows ALPC Elevation of Privilege Vulnerability

CVE-2018-8414
HIGH · vendor

Windows Shell Remote Code Execution Vulnerability

CVE-2018-8406
HIGH · vendor

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2018-8405
HIGH · vendor

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2016-9079
HIGH 7.5

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a…

CVE-2018-8174
HIGH 7.5

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution …

CVE-2018-0824
HIGH · vendor

Microsoft COM for Windows Remote Code Execution Vulnerability

CVE-2018-0802
HIGH 7.8

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability d…

CVE-2018-0798
HIGH 8.8

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability …

CVE-2017-11826
HIGH 7.8

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 200…

CVE-2017-11774
HIGH 7.8

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles …

CVE-2017-0263
HIGH · vendor

Win32k Elevation of Privilege Vulnerability

CVE-2017-0213
HIGH · vendor

Windows COM Elevation of Privilege Vulnerability

CVE-2017-0145
HIGH 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.…

CVE-2017-0144
HIGH 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.…

CVE-2017-0147
HIGH · vendor

Windows SMB Information Disclosure Vulnerability

CVE-2017-0005
HIGH · vendor

Windows GDI Elevation of Privilege Vulnerability

CVE-2017-0001
HIGH · vendor

Windows GDI Elevation of Privilege Vulnerability

CVE-2017-0037
HIGH 8.1

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningEle…

CVE-2016-7262
HIGH 7.8

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted re…

CVE-2016-7255
HIGH 7.8

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window…

CVE-2016-7201
HIGH 8.8

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via…

CVE-2016-7200
HIGH 8.8

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via…

CVE-2016-7193
HIGH 7.8

Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word…

CVE-2016-3309
HIGH · vendor

Windows Kernel Elevation of Privilege Vulnerability

CVE-2016-0167
HIGH 7.8

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows…

CVE-2016-0165
HIGH 7.8

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows…

CVE-2016-0151
HIGH 7.8

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages…

CVE-2013-1690
HIGH 8.8

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadyst…

CVE-2012-1854
HIGH 7.8

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications …

CVE-2009-3459
HIGH 8.8

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code…

CVE-2009-0556
HIGH 8.8

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary cod…

CVE-2009-0238
HIGH 8.8

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerP…

CVE-2007-0671
HIGH 8.8

Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to exe…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM