Skip to content
Appaloosa Scout
Language selector
fr en

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

372 actively exploited CVEs (all severities, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.

Matching CVEs
372
Actively exploited
372
Publication window
2007-02-03 → 2026-09-09

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

372 entries CISA KEV Clear all
CVE
CVE-2024-38217
MEDIUM 5.4

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-38014
HIGH 7.8

Windows Installer Elevation of Privilege Vulnerability

CVE-2024-32896
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-7971
CRITICAL 9.6

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security s…

CVE-2024-7965
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

CVE-2024-38213
MEDIUM · vendor

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-38193
HIGH · vendor

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2024-38178
HIGH · vendor

Scripting Engine Memory Corruption Vulnerability

CVE-2024-38107
HIGH · vendor

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

CVE-2024-38106
HIGH · vendor

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-36971
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-38112
HIGH · vendor

Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-38080
HIGH · vendor

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2024-39891
MEDIUM 5.3

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-numb…

CVE-2024-4610
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-35250
HIGH 7.8

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

CVE-2024-30088
HIGH 7.0

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-5274
CRITICAL 9.6

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…

CVE-2024-4947
CRITICAL 9.6

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chr…

CVE-2024-4761
HIGH 8.8

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. …

CVE-2024-4671
CRITICAL 9.6

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a …

CVE-2024-30051
HIGH · vendor

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2024-30040
HIGH · vendor

Windows MSHTML Platform Security Feature Bypass Vulnerability

CVE-2024-29988
HIGH · vendor

SmartScreen Prompt Security Feature Bypass Vulnerability

CVE-2024-26169
HIGH · vendor

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2024-23296
HIGH 7.8

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey…

CVE-2024-23225
HIGH 7.8

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey…

CVE-2024-21413
CRITICAL 9.8

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2024-21412
HIGH 8.1

Internet Shortcut Files Security Feature Bypass Vulnerability

CVE-2024-21351
HIGH 7.6

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2024-21338
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-23222
HIGH 8.8

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS …

CVE-2024-0519
HIGH 8.8

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

CVE-2023-41974
HIGH 7.8

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be …

CVE-2023-7024
HIGH 8.8

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

CVE-2023-33107
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-33106
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-33063
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-42917
HIGH 8.8

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2.…

CVE-2023-42916
MEDIUM 6.5

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Pr…

CVE-2023-6345
CRITICAL 9.6

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a s…

CVE-2023-36424
HIGH · vendor

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-36036
HIGH · vendor

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-36033
HIGH · vendor

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2023-36025
HIGH · vendor

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2023-44487
HIGH 7.5

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w…

CVE-2023-36584
HIGH · vendor

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2023-36563
HIGH · vendor

Microsoft WordPad Information Disclosure Vulnerability

CVE-2023-4211
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-5217
HIGH 8.8

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM