KEV CISA
Vulnérabilités activement exploitées (KEV CISA)
372 CVE activement exploitées (toutes sévérités, toutes plateformes) touchent une app ou un OS suivi. La CISA confirme leur exploitation pour chacune.
- CVE correspondantes
- 372
- Activement exploitées
- 372
- Fenêtre de publication
- 2007-02-03 → 2026-09-09
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2019-1322
HIGH · éditeur
Microsoft Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1315
HIGH · éditeur
Windows Error Reporting Manager Elevation of Privilege Vulnerability |
|
CVE-2019-2215
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2019-1297
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Rem… |
|
CVE-2019-1253
HIGH · éditeur
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1215
HIGH · éditeur
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1214
HIGH · éditeur
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2019-11708
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op… |
|
CVE-2019-11707
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware… |
|
CVE-2019-1130
HIGH 7.8
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privileg… |
|
CVE-2019-1129
HIGH · éditeur
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0880
HIGH · éditeur
Microsoft splwow64 Elevation of Privilege Vulnerability |
|
CVE-2019-1069
HIGH 7.8
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited … |
|
CVE-2019-1064
HIGH · éditeur
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0903
CRITICAL · éditeur
GDI+ Remote Code Execution Vulnerability |
|
CVE-2019-0863
HIGH · éditeur
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2019-0859
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2019-0841
HIGH · éditeur
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0803
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2019-0797
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2019-0703
HIGH · éditeur
Windows SMB Information Disclosure Vulnerability |
|
CVE-2018-20250
HIGH 7.8
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When… |
|
CVE-2019-0543
HIGH · éditeur
Microsoft Windows Elevation of Privilege Vulnerability |
|
CVE-2018-8639
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2018-8611
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8453
HIGH 7.8
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privil… |
|
CVE-2018-8440
HIGH · éditeur
Windows ALPC Elevation of Privilege Vulnerability |
|
CVE-2018-8414
HIGH · éditeur
Windows Shell Remote Code Execution Vulnerability |
|
CVE-2018-8406
HIGH · éditeur
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8405
HIGH · éditeur
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2016-9079
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a… |
|
CVE-2018-8174
HIGH 7.5
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution … |
|
CVE-2018-0824
HIGH · éditeur
Microsoft COM for Windows Remote Code Execution Vulnerability |
|
CVE-2018-0802
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability d… |
|
CVE-2018-0798
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability … |
|
CVE-2017-11826
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 200… |
|
CVE-2017-11774
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles … |
|
CVE-2017-8543
CRITICAL · éditeur
Windows Search Remote Code Execution Vulnerability |
|
CVE-2017-8464
CRITICAL · éditeur
LNK Remote Code Execution Vulnerability |
|
CVE-2017-0263
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2017-0213
HIGH · éditeur
Windows COM Elevation of Privilege Vulnerability |
|
CVE-2017-0145
HIGH 8.8
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.… |
|
CVE-2017-0144
HIGH 8.8
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.… |
|
CVE-2017-0148
CRITICAL · éditeur
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0147
HIGH · éditeur
Windows SMB Information Disclosure Vulnerability |
|
CVE-2017-0146
CRITICAL · éditeur
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0143
CRITICAL · éditeur
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0005
HIGH · éditeur
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2017-0001
HIGH · éditeur
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2017-0037
HIGH 8.1
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningEle… |