Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

KEV CISA

Vulnérabilités activement exploitées (KEV CISA)

372 CVE activement exploitées (toutes sévérités, toutes plateformes) touchent une app ou un OS suivi. La CISA confirme leur exploitation pour chacune.

CVE correspondantes
372
Activement exploitées
372
Fenêtre de publication
2007-02-03 → 2026-09-09

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

372 entrées KEV CISA Tout effacer
CVE
CVE-2019-1322
HIGH · éditeur

Microsoft Windows Elevation of Privilege Vulnerability

CVE-2019-1315
HIGH · éditeur

Windows Error Reporting Manager Elevation of Privilege Vulnerability

CVE-2019-2215
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2019-1297
HIGH 8.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Rem…

CVE-2019-1253
HIGH · éditeur

Windows Elevation of Privilege Vulnerability

CVE-2019-1215
HIGH · éditeur

Windows Elevation of Privilege Vulnerability

CVE-2019-1214
HIGH · éditeur

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2019-11708
CRITICAL 10.0

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op…

CVE-2019-11707
HIGH 8.8

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware…

CVE-2019-1130
HIGH 7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privileg…

CVE-2019-1129
HIGH · éditeur

Windows Elevation of Privilege Vulnerability

CVE-2019-0880
HIGH · éditeur

Microsoft splwow64 Elevation of Privilege Vulnerability

CVE-2019-1069
HIGH 7.8

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited …

CVE-2019-1064
HIGH · éditeur

Windows Elevation of Privilege Vulnerability

CVE-2019-0903
CRITICAL · éditeur

GDI+ Remote Code Execution Vulnerability

CVE-2019-0863
HIGH · éditeur

Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2019-0859
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2019-0841
HIGH · éditeur

Windows Elevation of Privilege Vulnerability

CVE-2019-0803
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2019-0797
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2019-0703
HIGH · éditeur

Windows SMB Information Disclosure Vulnerability

CVE-2018-20250
HIGH 7.8

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When…

CVE-2019-0543
HIGH · éditeur

Microsoft Windows Elevation of Privilege Vulnerability

CVE-2018-8639
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2018-8611
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2018-8453
HIGH 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privil…

CVE-2018-8440
HIGH · éditeur

Windows ALPC Elevation of Privilege Vulnerability

CVE-2018-8414
HIGH · éditeur

Windows Shell Remote Code Execution Vulnerability

CVE-2018-8406
HIGH · éditeur

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2018-8405
HIGH · éditeur

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2016-9079
HIGH 7.5

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a…

CVE-2018-8174
HIGH 7.5

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution …

CVE-2018-0824
HIGH · éditeur

Microsoft COM for Windows Remote Code Execution Vulnerability

CVE-2018-0802
HIGH 7.8

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability d…

CVE-2018-0798
HIGH 8.8

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability …

CVE-2017-11826
HIGH 7.8

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 200…

CVE-2017-11774
HIGH 7.8

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles …

CVE-2017-8543
CRITICAL · éditeur

Windows Search Remote Code Execution Vulnerability

CVE-2017-8464
CRITICAL · éditeur

LNK Remote Code Execution Vulnerability

CVE-2017-0263
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2017-0213
HIGH · éditeur

Windows COM Elevation of Privilege Vulnerability

CVE-2017-0145
HIGH 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.…

CVE-2017-0144
HIGH 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.…

CVE-2017-0148
CRITICAL · éditeur

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0147
HIGH · éditeur

Windows SMB Information Disclosure Vulnerability

CVE-2017-0146
CRITICAL · éditeur

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0143
CRITICAL · éditeur

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0005
HIGH · éditeur

Windows GDI Elevation of Privilege Vulnerability

CVE-2017-0001
HIGH · éditeur

Windows GDI Elevation of Privilege Vulnerability

CVE-2017-0037
HIGH 8.1

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningEle…