Skip to content
Appaloosa Scout
Language selector
fr en

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

47 actively exploited CVEs (Critical, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.

Matching CVEs
47
Actively exploited
47
Publication window
2010-10-28 → 2026-08-06

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

47 entries Critical CISA KEV Clear all
CVE
CVE-2026-65400
CRITICAL 9.8

An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, m…

CVE-2026-33824
CRITICAL 9.8

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

CVE-2025-59287
CRITICAL · vendor

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2025-10585
CRITICAL 9.8

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2025-39682
CRITICAL 9.8

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process …

CVE-2025-43300
CRITICAL 10.0

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, …

CVE-2025-21479
CRITICAL · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-31201
CRITICAL 9.8

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.…

CVE-2025-31200
CRITICAL 9.8

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, …

CVE-2025-24201
CRITICAL 10.0

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15…

CVE-2025-24085
CRITICAL 10.0

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS…

CVE-2024-9680
CRITICAL 9.8

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner…

CVE-2024-7971
CRITICAL 9.6

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security s…

CVE-2024-5274
CRITICAL 9.6

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch…

CVE-2024-4947
CRITICAL 9.6

Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chr…

CVE-2024-4671
CRITICAL 9.6

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a …

CVE-2024-21413
CRITICAL 9.8

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2023-6345
CRITICAL 9.6

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a s…

CVE-2023-2136
CRITICAL 9.6

Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a s…

CVE-2023-23397
CRITICAL 9.8

Microsoft Outlook Elevation of Privilege Vulnerability

CVE-2022-4135
CRITICAL 9.6

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform …

CVE-2022-3075
CRITICAL 9.6

Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially…

CVE-2022-26923
CRITICAL · vendor

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2021-44228
CRITICAL 10.0

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter…

CVE-2021-37973
CRITICAL 9.6

Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sa…

CVE-2021-30633
CRITICAL 9.6

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perfo…

CVE-2021-33742
CRITICAL · vendor

Windows MSHTML Platform Remote Code Execution Vulnerability

CVE-2021-31166
CRITICAL · vendor

HTTP Protocol Stack Remote Code Execution Vulnerability

CVE-2020-15999
CRITICAL 9.6

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa…

CVE-2020-1472
CRITICAL · vendor

Netlogon Elevation of Privilege Vulnerability

CVE-2020-1350
CRITICAL · vendor

Windows DNS Server Remote Code Execution Vulnerability

CVE-2020-1040
CRITICAL · vendor

Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

CVE-2020-1020
CRITICAL · vendor

Adobe Font Manager Library Remote Code Execution Vulnerability

CVE-2020-0938
CRITICAL · vendor

Adobe Font Manager Library Remote Code Execution Vulnerability

CVE-2020-0796
CRITICAL 10.0

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S…

CVE-2019-11708
CRITICAL 10.0

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op…

CVE-2019-0903
CRITICAL · vendor

GDI+ Remote Code Execution Vulnerability

CVE-2017-8543
CRITICAL · vendor

Windows Search Remote Code Execution Vulnerability

CVE-2017-8464
CRITICAL · vendor

LNK Remote Code Execution Vulnerability

CVE-2017-0148
CRITICAL · vendor

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0146
CRITICAL · vendor

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0143
CRITICAL · vendor

Windows SMB Remote Code Execution Vulnerability

CVE-2016-5195
CRITICAL · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2016-7256
CRITICAL · vendor

Microsoft Graphics Remote Code Execution Vulnerability

CVE-2016-3393
CRITICAL · vendor

GDI+ Remote Code Execution Vulnerability

CVE-2014-0497
CRITICAL 9.8

Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linu…

CVE-2010-3765
CRITICAL 9.8

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when Ja…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM