CISA KEV
Actively exploited vulnerabilities (CISA KEV)
47 actively exploited CVEs (Critical, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.
- Matching CVEs
- 47
- Actively exploited
- 47
- Publication window
- 2010-10-28 → 2026-08-06
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-65400
CRITICAL 9.8
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, m… |
|
CVE-2026-33824
CRITICAL 9.8
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
|
CVE-2025-59287
CRITICAL · vendor
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
|
CVE-2025-10585
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2025-39682
CRITICAL 9.8
In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process … |
|
CVE-2025-43300
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, … |
|
CVE-2025-21479
CRITICAL · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-31201
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.… |
|
CVE-2025-31200
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, … |
|
CVE-2025-24201
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15… |
|
CVE-2025-24085
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS… |
|
CVE-2024-9680
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner… |
|
CVE-2024-7971
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security s… |
|
CVE-2024-5274
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch… |
|
CVE-2024-4947
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chr… |
|
CVE-2024-4671
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a … |
|
CVE-2024-21413
Microsoft Outlook Remote Code Execution Vulnerability |
|
CVE-2023-6345
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a s… |
|
CVE-2023-2136
CRITICAL 9.6
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a s… |
|
CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability |
|
CVE-2022-4135
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform … |
|
CVE-2022-3075
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially… |
|
CVE-2022-26923
CRITICAL · vendor
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-44228
CRITICAL 10.0
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter… |
|
CVE-2021-37973
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sa… |
|
CVE-2021-30633
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perfo… |
|
CVE-2021-33742
CRITICAL · vendor
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-31166
CRITICAL · vendor
HTTP Protocol Stack Remote Code Execution Vulnerability |
|
CVE-2020-15999
CRITICAL 9.6
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… |
|
CVE-2020-1472
CRITICAL · vendor
Netlogon Elevation of Privilege Vulnerability |
|
CVE-2020-1350
CRITICAL · vendor
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2020-1040
CRITICAL · vendor
Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability |
|
CVE-2020-1020
CRITICAL · vendor
Adobe Font Manager Library Remote Code Execution Vulnerability |
|
CVE-2020-0938
CRITICAL · vendor
Adobe Font Manager Library Remote Code Execution Vulnerability |
|
CVE-2020-0796
CRITICAL 10.0
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S… |
|
CVE-2019-11708
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op… |
|
CVE-2019-0903
CRITICAL · vendor
GDI+ Remote Code Execution Vulnerability |
|
CVE-2017-8543
CRITICAL · vendor
Windows Search Remote Code Execution Vulnerability |
|
CVE-2017-8464
CRITICAL · vendor
LNK Remote Code Execution Vulnerability |
|
CVE-2017-0148
CRITICAL · vendor
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0146
CRITICAL · vendor
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0143
CRITICAL · vendor
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2016-5195
CRITICAL · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-7256
CRITICAL · vendor
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2016-3393
CRITICAL · vendor
GDI+ Remote Code Execution Vulnerability |
|
CVE-2014-0497
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linu… |
|
CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when Ja… |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.