Skip to content
Appaloosa Scout

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

285 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2021-1905
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2021-28310
HIGH 7.8 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2021-1732
HIGH 7.8 KEV

Windows Win32k Elevation of Privilege Vulnerability

CVE-2020-11261
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2020-17087
HIGH 7.8 KEV

Windows Kernel Local Elevation of Privilege Vulnerability

CVE-2020-15999
CRITICAL 9.6 KEV Network

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

CVE-2020-1472
CRITICAL 10.0 KEV

Netlogon Elevation of Privilege Vulnerability

CVE-2020-1464
HIGH 5.3 KEV

Windows Spoofing Vulnerability

CVE-2020-1350
CRITICAL 10.0 KEV

Windows DNS Server Remote Code Execution Vulnerability

CVE-2020-1040
CRITICAL 8.0 KEV

Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

CVE-2020-0986
HIGH KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2020-1054
HIGH 7.0 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2020-6820
HIGH 8.1 KEV Network 1 apps

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing thi…

CVE-2020-6819
HIGH 8.1 KEV Network 1 apps

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abu…

CVE-2020-1027
HIGH 7.8 KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2020-1020
CRITICAL 7.8 KEV

Adobe Font Manager Library Remote Code Execution Vulnerability

CVE-2020-0938
CRITICAL 7.8 KEV

Adobe Font Manager Library Remote Code Execution Vulnerability

CVE-2020-0796
CRITICAL 10.0 KEV

Windows SMBv3 Client/Server Remote Code Execution Vulnerability

CVE-2020-0787
HIGH 7.8 KEV

Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability

CVE-2019-17026
HIGH 8.8 KEV Network 1 apps

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild a…

CVE-2020-0069
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2020-0041
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2020-0683
HIGH 7.0 KEV

Windows Installer Elevation of Privilege Vulnerability

CVE-2019-18426
HIGH 8.2 KEV Network 1 apps

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and l…

CVE-2020-0638
HIGH 7.8 KEV

Update Notification Manager Elevation of Privilege Vulnerability

CVE-2020-0601
HIGH 8.1 KEV

Windows CryptoAPI Spoofing Vulnerability

CVE-2019-1458
HIGH 7.8 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2019-1405
HIGH 7.8 KEV

Windows UPnP Service Elevation of Privilege Vulnerability

CVE-2019-1388
HIGH 7.8 KEV

Windows Certificate Dialog Elevation of Privilege Vulnerability

CVE-2019-1385
HIGH 7.8 KEV

Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

CVE-2019-1322
HIGH 7.0 KEV

Microsoft Windows Elevation of Privilege Vulnerability

CVE-2019-1315
HIGH 7.8 KEV

Windows Error Reporting Manager Elevation of Privilege Vulnerability

CVE-2019-2215
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2019-1253
HIGH 7.8 KEV

Windows Elevation of Privilege Vulnerability

CVE-2019-1215
HIGH 7.8 KEV

Windows Elevation of Privilege Vulnerability

CVE-2019-1214
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2019-11708
CRITICAL 10.0 KEV Network 1 apps

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op…

CVE-2019-11707
HIGH 8.8 KEV Network 1 apps

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware…

CVE-2019-1130
HIGH 7.8 KEV

Windows Elevation of Privilege Vulnerability

CVE-2019-1129
HIGH 7.8 KEV

Windows Elevation of Privilege Vulnerability

CVE-2019-0880
HIGH 7.0 KEV

Microsoft splwow64 Elevation of Privilege Vulnerability

CVE-2019-1069
HIGH 7.8 KEV

Task Scheduler Elevation of Privilege Vulnerability

CVE-2019-1064
HIGH 7.8 KEV

Windows Elevation of Privilege Vulnerability

CVE-2019-0903
CRITICAL 8.8 KEV

GDI+ Remote Code Execution Vulnerability

CVE-2019-0863
HIGH 7.8 KEV

Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2019-0859
HIGH 7.8 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2019-0841
HIGH 6.8 KEV

Windows Elevation of Privilege Vulnerability

CVE-2019-0803
HIGH 7.0 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2019-0797
HIGH 7.0 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2019-0703
HIGH 6.5 KEV

Windows SMB Information Disclosure Vulnerability