CISA KEV
Actively exploited vulnerabilities (CISA KEV)
213 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2022-26925
HIGH 8.1
KEV
Windows LSA Spoofing Vulnerability |
|
CVE-2022-26923
CRITICAL 8.8
KEV
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2022-26904
HIGH 7.0
KEV
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2022-24521
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2022-22718
HIGH 7.8
KEV
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-21999
HIGH 7.8
KEV
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-21971
HIGH 7.8
KEV
Windows Runtime Remote Code Execution Vulnerability |
|
CVE-2022-21919
HIGH 7.0
KEV
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2022-21882
HIGH 7.0
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2013-3900
MEDIUM 5.5
KEV
WinVerifyTrust Signature Validation Vulnerability |
|
CVE-2021-43226
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2021-42287
HIGH 7.5
KEV
Network
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-42278
HIGH 7.5
KEV
Network
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-41379
HIGH 5.5
KEV
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2021-41357
HIGH 7.8
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-40450
HIGH 7.8
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-40449
HIGH 7.8
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-40444
HIGH 8.8
KEV
Network
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks th… |
|
CVE-2021-36955
HIGH 7.8
KEV
Local
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2021-36948
HIGH 7.8
KEV
Local
Windows Update Medic Service Elevation of Privilege Vulnerability |
|
CVE-2021-36942
HIGH 7.5
KEV
Network
Windows LSA Spoofing Vulnerability |
|
CVE-2021-34486
HIGH 7.8
KEV
Local
Windows Event Tracing Elevation of Privilege Vulnerability |
|
CVE-2021-34484
HIGH 7.8
KEV
Local
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2021-36934
HIGH 7.8
KEV
Local
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accoun… |
|
CVE-2021-34448
MEDIUM 6.8
KEV
Network
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-33771
HIGH 7.8
KEV
Local
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2021-31979
HIGH 7.8
KEV
Local
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2021-34527
HIGH 8.8
KEV
Network
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull… |
|
CVE-2021-1675
HIGH 7.8
KEV
Local
Windows Print Spooler Remote Code Execution Vulnerability |
|
CVE-2021-33742
CRITICAL 7.5
KEV
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-33739
HIGH 8.4
KEV
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2021-31956
HIGH 7.8
KEV
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2021-31955
HIGH 5.5
KEV
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2021-31201
HIGH 5.2
KEV
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
|
CVE-2021-31199
HIGH 5.2
KEV
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
|
CVE-2021-31166
CRITICAL 9.8
KEV
HTTP Protocol Stack Remote Code Execution Vulnerability |
|
CVE-2021-28310
HIGH 7.8
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-1732
HIGH 7.8
KEV
Local
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2020-17087
HIGH 7.8
KEV
Windows Kernel Local Elevation of Privilege Vulnerability |
|
CVE-2020-1472
CRITICAL 10.0
KEV
Netlogon Elevation of Privilege Vulnerability |
|
CVE-2020-1464
HIGH 5.3
KEV
Windows Spoofing Vulnerability |
|
CVE-2020-1350
CRITICAL 10.0
KEV
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2020-1040
CRITICAL 8.0
KEV
Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability |
|
CVE-2020-0986
HIGH
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-1054
HIGH 7.0
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2020-6820
HIGH 8.1
KEV
Network 1 apps
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing thi… |
|
CVE-2020-6819
HIGH 8.1
KEV
Network 1 apps
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abu… |
|
CVE-2020-1027
HIGH 7.8
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-1020
CRITICAL 7.8
KEV
Adobe Font Manager Library Remote Code Execution Vulnerability |
|
CVE-2020-0938
CRITICAL 7.8
KEV
Adobe Font Manager Library Remote Code Execution Vulnerability |