Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

KEV CISA

Vulnérabilités activement exploitées (KEV CISA)

372 CVE activement exploitées (toutes sévérités, toutes plateformes) touchent une app ou un OS suivi. La CISA confirme leur exploitation pour chacune.

CVE correspondantes
372
Activement exploitées
372
Fenêtre de publication
2007-02-03 → 2026-09-09

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

372 entrées KEV CISA Tout effacer
CVE
CVE-2022-1364
HIGH 8.8

Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-1096
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-22047
HIGH · éditeur

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

CVE-2022-30190
HIGH 7.8

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully e…

CVE-2022-26925
HIGH · éditeur

Windows LSA Spoofing Vulnerability

CVE-2022-26923
CRITICAL · éditeur

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2022-26904
HIGH · éditeur

Windows User Profile Service Elevation of Privilege Vulnerability

CVE-2022-24521
HIGH · éditeur

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2022-0609
HIGH 8.8

Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-4102
HIGH 8.8

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-22718
HIGH · éditeur

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-21999
HIGH · éditeur

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-21971
HIGH · éditeur

Windows Runtime Remote Code Execution Vulnerability

CVE-2022-21882
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2022-21919
HIGH · éditeur

Windows User Profile Service Elevation of Privilege Vulnerability

CVE-2013-3900
MEDIUM · éditeur

WinVerifyTrust Signature Validation Vulnerability

CVE-2021-43226
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2021-44228
CRITICAL 10.0

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter…

CVE-2021-38003
HIGH 8.8

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

CVE-2021-38000
MEDIUM 6.1

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a m…

CVE-2021-42292
HIGH 7.8

Microsoft Excel Security Feature Bypass Vulnerability

CVE-2021-42287
HIGH 7.5

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2021-42278
HIGH 7.5

Active Directory Domain Services Elevation of Privilege Vulnerability

CVE-2021-41379
MEDIUM 5.5

Windows Installer Elevation of Privilege Vulnerability

CVE-2021-1048
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-0920
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-41357
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2021-40450
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2021-40449
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2021-37976
MEDIUM 6.5

Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from proces…

CVE-2021-37975
HIGH 8.8

Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-37973
CRITICAL 9.6

Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sa…

CVE-2021-30633
CRITICAL 9.6

Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perfo…

CVE-2021-30632
HIGH 8.8

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-40444
HIGH 8.8

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks th…

CVE-2021-38646
HIGH 7.8

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

CVE-2021-36955
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2021-36948
HIGH 7.8

Windows Update Medic Service Elevation of Privilege Vulnerability

CVE-2021-36942
HIGH 7.5

Windows LSA Spoofing Vulnerability

CVE-2021-34486
HIGH 7.8

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2021-34484
HIGH 7.8

Windows User Profile Service Elevation of Privilege Vulnerability

CVE-2021-30563
HIGH 8.8

Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-36934
HIGH 7.8

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accoun…

CVE-2021-34448
MEDIUM 6.8

Scripting Engine Memory Corruption Vulnerability

CVE-2021-33771
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2021-31979
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2021-34527
HIGH 8.8

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfull…

CVE-2021-30554
HIGH 8.8

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-30551
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-1675
HIGH 7.8

Windows Print Spooler Remote Code Execution Vulnerability