CISA KEV
Actively exploited vulnerabilities (CISA KEV)
294 actively exploited CVEs (High, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.
- Matching CVEs
- 294
- Actively exploited
- 294
- Publication window
- 2007-02-03 → 2026-09-09
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2019-0859
HIGH · vendor
Win32k Elevation of Privilege Vulnerability |
|
CVE-2019-0841
HIGH · vendor
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0803
HIGH · vendor
Win32k Elevation of Privilege Vulnerability |
|
CVE-2019-0797
HIGH · vendor
Win32k Elevation of Privilege Vulnerability |
|
CVE-2019-0703
HIGH · vendor
Windows SMB Information Disclosure Vulnerability |
|
CVE-2018-20250
HIGH 7.8
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When… |
|
CVE-2019-0543
HIGH · vendor
Microsoft Windows Elevation of Privilege Vulnerability |
|
CVE-2018-8639
HIGH · vendor
Win32k Elevation of Privilege Vulnerability |
|
CVE-2018-8611
HIGH · vendor
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8453
HIGH 7.8
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privil… |
|
CVE-2018-8440
HIGH · vendor
Windows ALPC Elevation of Privilege Vulnerability |
|
CVE-2018-8414
HIGH · vendor
Windows Shell Remote Code Execution Vulnerability |
|
CVE-2018-8406
HIGH · vendor
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8405
HIGH · vendor
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2016-9079
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a… |
|
CVE-2018-8174
HIGH 7.5
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution … |
|
CVE-2018-0824
HIGH · vendor
Microsoft COM for Windows Remote Code Execution Vulnerability |
|
CVE-2018-0802
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability d… |
|
CVE-2018-0798
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability … |
|
CVE-2017-11826
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 200… |
|
CVE-2017-11774
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles … |
|
CVE-2017-0263
HIGH · vendor
Win32k Elevation of Privilege Vulnerability |
|
CVE-2017-0213
HIGH · vendor
Windows COM Elevation of Privilege Vulnerability |
|
CVE-2017-0145
HIGH 8.8
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.… |
|
CVE-2017-0144
HIGH 8.8
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.… |
|
CVE-2017-0147
HIGH · vendor
Windows SMB Information Disclosure Vulnerability |
|
CVE-2017-0005
HIGH · vendor
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2017-0001
HIGH · vendor
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2017-0037
HIGH 8.1
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningEle… |
|
CVE-2016-7262
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted re… |
|
CVE-2016-7255
HIGH 7.8
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window… |
|
CVE-2016-7201
HIGH 8.8
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via… |
|
CVE-2016-7200
HIGH 8.8
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via… |
|
CVE-2016-7193
Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word… |
|
CVE-2016-3309
HIGH · vendor
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2016-0167
HIGH 7.8
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows… |
|
CVE-2016-0165
HIGH 7.8
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows… |
|
CVE-2016-0151
HIGH 7.8
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages… |
|
CVE-2013-1690
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadyst… |
|
CVE-2012-1854
Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications … |
|
CVE-2009-3459
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code… |
|
CVE-2009-0556
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary cod… |
|
CVE-2009-0238
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerP… |
|
CVE-2007-0671
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to exe… |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.