KEV CISA
Vulnérabilités activement exploitées (KEV CISA)
372 CVE activement exploitées (toutes sévérités, toutes plateformes) touchent une app ou un OS suivi. La CISA confirme leur exploitation pour chacune.
- CVE correspondantes
- 372
- Activement exploitées
- 372
- Fenêtre de publication
- 2007-02-03 → 2026-09-09
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-26369
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerabil… |
|
CVE-2023-36761
Microsoft Word Information Disclosure Vulnerability |
|
CVE-2023-4863
HIGH 8.8
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write v… |
|
CVE-2023-36802
HIGH · éditeur
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability |
|
CVE-2023-4762
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security s… |
|
CVE-2023-35674
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-38831
HIGH 7.8
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because … |
|
CVE-2023-36884
HIGH 7.5
Windows Search Remote Code Execution Vulnerability |
|
CVE-2023-35311
Microsoft Outlook Security Feature Bypass Vulnerability |
|
CVE-2023-36874
HIGH · éditeur
Windows Error Reporting Service Elevation of Privilege Vulnerability |
|
CVE-2023-32049
HIGH · éditeur
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-32046
HIGH · éditeur
Windows MSHTML Platform Elevation of Privilege Vulnerability |
|
CVE-2023-26083
MEDIUM · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-29256
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-29360
HIGH · éditeur
Microsoft Streaming Service Elevation of Privilege Vulnerability |
|
CVE-2023-3079
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2022-22706
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-29336
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-0266
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-0847
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-22600
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-2136
CRITICAL 9.6
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a s… |
|
CVE-2023-2033
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2023-28252
HIGH · éditeur
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-28229
HIGH · éditeur
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |
|
CVE-2022-38181
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability |
|
CVE-2023-24880
MEDIUM · éditeur
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-20963
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-21823
HIGH 7.8
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2023-23376
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-21608
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerabil… |
|
CVE-2023-21674
HIGH · éditeur
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability |
|
CVE-2022-44698
MEDIUM · éditeur
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-4262
Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… |
|
CVE-2022-4135
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform … |
|
CVE-2022-41128
HIGH 8.8
Windows Scripting Languages Remote Code Execution Vulnerability |
|
CVE-2022-41125
HIGH 7.8
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |
|
CVE-2022-41091
MEDIUM 5.4
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2022-41073
HIGH 7.8
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-41049
MEDIUM 5.4
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2022-3723
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… |
|
CVE-2022-41033
HIGH · éditeur
Windows COM+ Event System Service Elevation of Privilege Vulnerability |
|
CVE-2022-38028
HIGH · éditeur
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-3075
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially… |
|
CVE-2022-3038
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p… |
|
CVE-2022-2856
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a … |
|
CVE-2022-37969
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2022-34713
HIGH · éditeur
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability |
|
CVE-2022-2294
Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… |