KEV CISA
Vulnérabilités activement exploitées (KEV CISA)
372 CVE activement exploitées (toutes sévérités, toutes plateformes) touchent une app ou un OS suivi. La CISA confirme leur exploitation pour chacune.
- CVE correspondantes
- 372
- Activement exploitées
- 372
- Fenêtre de publication
- 2007-02-03 → 2026-09-09
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2022-1364
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2022-1096
Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2022-22047
HIGH · éditeur
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability |
|
CVE-2022-30190
HIGH 7.8
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully e… |
|
CVE-2022-26925
HIGH · éditeur
Windows LSA Spoofing Vulnerability |
|
CVE-2022-26923
CRITICAL · éditeur
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2022-26904
HIGH · éditeur
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2022-24521
HIGH · éditeur
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2022-0609
Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-4102
Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2022-22718
HIGH · éditeur
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-21999
HIGH · éditeur
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-21971
HIGH · éditeur
Windows Runtime Remote Code Execution Vulnerability |
|
CVE-2022-21882
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2022-21919
HIGH · éditeur
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2013-3900
MEDIUM · éditeur
WinVerifyTrust Signature Validation Vulnerability |
|
CVE-2021-43226
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2021-44228
CRITICAL 10.0
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter… |
|
CVE-2021-38003
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p… |
|
CVE-2021-38000
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a m… |
|
CVE-2021-42292
Microsoft Excel Security Feature Bypass Vulnerability |
|
CVE-2021-42287
HIGH 7.5
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-42278
HIGH 7.5
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-41379
MEDIUM 5.5
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2021-1048
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-0920
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-41357
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-40450
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-40449
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-37976
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from proces… |
|
CVE-2021-37975
Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-37973
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sa… |
|
CVE-2021-30633
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perfo… |
|
CVE-2021-30632
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-40444
HIGH 8.8
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks th… |
|
CVE-2021-38646
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability |
|
CVE-2021-36955
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2021-36948
HIGH 7.8
Windows Update Medic Service Elevation of Privilege Vulnerability |
|
CVE-2021-36942
HIGH 7.5
Windows LSA Spoofing Vulnerability |
|
CVE-2021-34486
HIGH 7.8
Windows Event Tracing Elevation of Privilege Vulnerability |
|
CVE-2021-34484
HIGH 7.8
Windows User Profile Service Elevation of Privilege Vulnerability |
|
CVE-2021-30563
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-36934
HIGH 7.8
An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accoun… |
|
CVE-2021-34448
MEDIUM 6.8
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-33771
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2021-31979
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2021-34527
HIGH 8.8
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull… |
|
CVE-2021-30554
Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-30551
Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-1675
HIGH 7.8
Windows Print Spooler Remote Code Execution Vulnerability |