Skip to content
Appaloosa Scout

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

177 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2021-41379
HIGH 5.5 KEV

Windows Installer Elevation of Privilege Vulnerability

CVE-2021-41357
HIGH 7.8 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2021-40450
HIGH 7.8 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2021-40449
HIGH 7.8 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2021-40444
HIGH 8.8 KEV Network

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks th…

CVE-2021-36955
HIGH 7.8 KEV Local

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2021-36948
HIGH 7.8 KEV Local

Windows Update Medic Service Elevation of Privilege Vulnerability

CVE-2021-36942
HIGH 7.5 KEV Network

Windows LSA Spoofing Vulnerability

CVE-2021-34486
HIGH 7.8 KEV Local

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2021-34484
HIGH 7.8 KEV Local

Windows User Profile Service Elevation of Privilege Vulnerability

CVE-2021-36934
HIGH 7.8 KEV Local

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accoun…

CVE-2021-33771
HIGH 7.8 KEV Local

Windows Kernel Elevation of Privilege Vulnerability

CVE-2021-31979
HIGH 7.8 KEV Local

Windows Kernel Elevation of Privilege Vulnerability

CVE-2021-34527
HIGH 8.8 KEV Network

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull…

CVE-2021-1675
HIGH 7.8 KEV Local

Windows Print Spooler Remote Code Execution Vulnerability

CVE-2021-33739
HIGH 8.4 KEV

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2021-31956
HIGH 7.8 KEV

Windows NTFS Elevation of Privilege Vulnerability

CVE-2021-31955
HIGH 5.5 KEV

Windows Kernel Information Disclosure Vulnerability

CVE-2021-31201
HIGH 5.2 KEV

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVE-2021-31199
HIGH 5.2 KEV

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

CVE-2021-28310
HIGH 7.8 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2021-1732
HIGH 7.8 KEV Local

Windows Win32k Elevation of Privilege Vulnerability

CVE-2020-17087
HIGH 7.8 KEV

Windows Kernel Local Elevation of Privilege Vulnerability

CVE-2020-1464
HIGH 5.3 KEV

Windows Spoofing Vulnerability

CVE-2020-0986
HIGH KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2020-1054
HIGH 7.0 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2020-6820
HIGH 8.1 KEV Network 1 apps

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing thi…

CVE-2020-6819
HIGH 8.1 KEV Network 1 apps

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abu…

CVE-2020-1027
HIGH 7.8 KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2020-0787
HIGH 7.8 KEV Local

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows …

CVE-2019-17026
HIGH 8.8 KEV Network 1 apps

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild a…

CVE-2020-0683
HIGH 7.0 KEV

Windows Installer Elevation of Privilege Vulnerability

CVE-2020-0638
HIGH 7.8 KEV Local

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first …

CVE-2020-0601
HIGH 8.1 KEV

Windows CryptoAPI Spoofing Vulnerability

CVE-2019-1458
HIGH 7.8 KEV Local

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privil…

CVE-2019-1405
HIGH 7.8 KEV Local

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP…

CVE-2019-1385
HIGH 7.8 KEV Local

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to sys…

CVE-2019-1388
HIGH 7.8 KEV

Windows Certificate Dialog Elevation of Privilege Vulnerability

CVE-2019-1322
HIGH 7.0 KEV

Microsoft Windows Elevation of Privilege Vulnerability

CVE-2019-1315
HIGH 7.8 KEV

Windows Error Reporting Manager Elevation of Privilege Vulnerability

CVE-2019-1253
HIGH 7.8 KEV

Windows Elevation of Privilege Vulnerability

CVE-2019-1215
HIGH 7.8 KEV

Windows Elevation of Privilege Vulnerability

CVE-2019-1214
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2019-11707
HIGH 8.8 KEV Network 1 apps

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware…

CVE-2019-1130
HIGH 7.8 KEV Local

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privileg…

CVE-2019-1129
HIGH 7.8 KEV

Windows Elevation of Privilege Vulnerability

CVE-2019-0880
HIGH 7.0 KEV

Microsoft splwow64 Elevation of Privilege Vulnerability

CVE-2019-1069
HIGH 7.8 KEV Local

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited …

CVE-2019-1064
HIGH 7.8 KEV

Windows Elevation of Privilege Vulnerability

CVE-2019-0863
HIGH 7.8 KEV

Windows Error Reporting Elevation of Privilege Vulnerability