CISA KEV
Actively exploited vulnerabilities (CISA KEV)
212 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-56155
HIGH 7.8
KEV
Local
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-32202
HIGH 4.3
KEV
Windows Shell Spoofing Vulnerability |
|
CVE-2026-21533
HIGH 7.8
KEV
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
|
CVE-2026-21525
MEDIUM 6.2
KEV
Windows Remote Access Connection Manager Denial of Service Vulnerability |
|
CVE-2026-21519
HIGH 7.8
KEV
Desktop Window Manager Elevation of Privilege Vulnerability |
|
CVE-2026-21513
HIGH 8.8
KEV
MSHTML Framework Security Feature Bypass Vulnerability |
|
CVE-2026-21510
HIGH 8.8
KEV
Windows Shell Security Feature Bypass Vulnerability |
|
CVE-2026-20805
MEDIUM 5.5
KEV
Local
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. |
|
CVE-2025-62221
HIGH 7.8
KEV
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2025-62215
HIGH 7.0
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-60710
HIGH 7.8
KEV
Host Process for Windows Tasks Elevation of Privilege Vulnerability |
|
CVE-2025-59287
CRITICAL 9.8
KEV
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
|
CVE-2025-59230
HIGH 7.8
KEV
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2025-47827
HIGH 4.6
KEV
MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11 |
|
CVE-2025-24990
HIGH 7.8
KEV
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-8088
HIGH 8.8
KEV
Network 1 apps
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This… |
|
CVE-2025-48384
HIGH 8.0
KEV
Network 2 apps
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to int… |
|
CVE-2025-6218
HIGH 7.8
KEV
Local 1 apps
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install… |
|
CVE-2025-33073
HIGH 8.8
KEV
Windows SMB Client Elevation of Privilege Vulnerability |
|
CVE-2025-33053
HIGH 8.8
KEV
Internet Shortcut Files Remote Code Execution Vulnerability |
|
CVE-2025-32709
HIGH 7.8
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-32706
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-32701
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-30400
HIGH 7.8
KEV
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-30397
HIGH 7.5
KEV
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2025-29824
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-26633
HIGH 7.0
KEV
Local
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-24993
HIGH 7.8
KEV
Windows NTFS Remote Code Execution Vulnerability |
|
CVE-2025-24991
HIGH 5.5
KEV
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24985
HIGH 7.8
KEV
Windows Fast FAT File System Driver Remote Code Execution Vulnerability |
|
CVE-2025-24984
HIGH 4.6
KEV
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24983
HIGH 7.0
KEV
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-24054
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-21418
HIGH 7.8
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-21391
HIGH 7.1
KEV
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2025-0411
HIGH 7.0
KEV
Local 1 apps
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installat… |
|
CVE-2025-21335
HIGH 7.8
KEV
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2025-21334
HIGH 7.8
KEV
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2025-21333
HIGH 7.8
KEV
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2024-49138
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-49039
HIGH 8.8
KEV
Local
Windows Task Scheduler Elevation of Privilege Vulnerability |
|
CVE-2024-43451
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2024-9680
CRITICAL 9.8
KEV
Network 1 apps
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner… |
|
CVE-2024-43573
MEDIUM 6.5
KEV
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-43572
HIGH 7.8
KEV
Microsoft Management Console Remote Code Execution Vulnerability |
|
CVE-2024-43461
HIGH 8.8
KEV
Network
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-38217
MEDIUM 5.4
KEV
Network
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-38014
HIGH 7.8
KEV
Local
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2024-38213
MEDIUM 6.5
KEV
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-38193
HIGH 7.8
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |