KEV CISA
Vulnérabilités activement exploitées (KEV CISA)
372 CVE activement exploitées (toutes sévérités, toutes plateformes) touchent une app ou un OS suivi. La CISA confirme leur exploitation pour chacune.
- CVE correspondantes
- 372
- Activement exploitées
- 372
- Fenêtre de publication
- 2007-02-03 → 2026-09-09
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2021-33742
CRITICAL · éditeur
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-33739
HIGH · éditeur
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2021-31956
HIGH · éditeur
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2021-31955
HIGH · éditeur
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2021-31201
HIGH · éditeur
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
|
CVE-2021-31199
HIGH · éditeur
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability |
|
CVE-2021-30533
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafte… |
|
CVE-2021-31166
CRITICAL · éditeur
HTTP Protocol Stack Remote Code Execution Vulnerability |
|
CVE-2021-28664
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-28663
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-1906
MEDIUM · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-1905
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-21224
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. |
|
CVE-2021-21220
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a… |
|
CVE-2021-21206
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-28310
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-21193
Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-27059
Microsoft Office Remote Code Execution Vulnerability |
|
CVE-2021-26411
HIGH 8.8
Internet Explorer Memory Corruption Vulnerability |
|
CVE-2021-21166
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2021-1732
HIGH 7.8
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2021-21148
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|
CVE-2020-11261
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2020-17087
HIGH · éditeur
Windows Kernel Local Elevation of Privilege Vulnerability |
|
CVE-2020-15999
CRITICAL 9.6
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… |
|
CVE-2020-0878
MEDIUM 4.2
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way th… |
|
CVE-2020-1472
CRITICAL · éditeur
Netlogon Elevation of Privilege Vulnerability |
|
CVE-2020-1464
HIGH · éditeur
Windows Spoofing Vulnerability |
|
CVE-2020-1350
CRITICAL · éditeur
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2020-1040
CRITICAL · éditeur
Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability |
|
CVE-2020-0986
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-1054
HIGH 7.0
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who succe… |
|
CVE-2020-6820
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing thi… |
|
CVE-2020-6819
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abu… |
|
CVE-2020-1027
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-1020
CRITICAL · éditeur
Adobe Font Manager Library Remote Code Execution Vulnerability |
|
CVE-2020-0938
CRITICAL · éditeur
Adobe Font Manager Library Remote Code Execution Vulnerability |
|
CVE-2020-0796
CRITICAL 10.0
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S… |
|
CVE-2020-0787
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows … |
|
CVE-2019-17026
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild a… |
|
CVE-2020-0069
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2020-0041
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2020-0683
HIGH · éditeur
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2019-18426
HIGH 8.2
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and l… |
|
CVE-2020-0638
HIGH 7.8
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first … |
|
CVE-2020-0601
HIGH · éditeur
Windows CryptoAPI Spoofing Vulnerability |
|
CVE-2019-1458
HIGH 7.8
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privil… |
|
CVE-2019-1405
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP… |
|
CVE-2019-1385
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to sys… |
|
CVE-2019-1388
HIGH · éditeur
Windows Certificate Dialog Elevation of Privilege Vulnerability |