KEV CISA
Vulnérabilités activement exploitées (KEV CISA)
48 CVE activement exploitées (toutes sévérités, Windows) touchent une app ou un OS suivi. La CISA confirme leur exploitation pour chacune.
- CVE correspondantes
- 48
- Activement exploitées
- 213
- Fenêtre de publication
- 2010-10-28 → 2026-04-14
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-32202
MEDIUM 4.3
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2025-59287
CRITICAL 9.8
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
|
CVE-2025-33073
HIGH 8.8
Windows SMB Client Elevation of Privilege Vulnerability |
|
CVE-2025-30397
HIGH 7.5
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2025-26633
HIGH 7.0
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-24054
HIGH 6.5
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-21333
HIGH 7.8
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2024-49138
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38193
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2024-21338
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-44487
HIGH 7.5
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w… |
|
CVE-2023-29336
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2020-1472
CRITICAL 10.0
Netlogon Elevation of Privilege Vulnerability |
|
CVE-2020-0796
CRITICAL 10.0
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S… |
|
CVE-2019-17026
HIGH 8.8
1 app
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild a… |
|
CVE-2020-0683
HIGH 7.0
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2020-0601
HIGH 8.1
Windows CryptoAPI Spoofing Vulnerability |
|
CVE-2019-1458
HIGH 7.8
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privil… |
|
CVE-2019-1405
HIGH 7.8
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP… |
|
CVE-2019-1322
HIGH 7.0
Microsoft Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1253
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-1215
HIGH 7.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-11708
CRITICAL 10.0
1 app
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op… |
|
CVE-2019-11707
HIGH 8.8
1 app
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware… |
|
CVE-2019-0863
HIGH 7.8
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2019-0841
HIGH 6.8
Windows Elevation of Privilege Vulnerability |
|
CVE-2019-0803
HIGH 7.0
Win32k Elevation of Privilege Vulnerability |
|
CVE-2018-20250
HIGH 7.8
1 app
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When… |
|
CVE-2019-0543
HIGH 7.8
Microsoft Windows Elevation of Privilege Vulnerability |
|
CVE-2018-8453
HIGH 7.8
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privil… |
|
CVE-2016-9079
HIGH 7.5
1 app
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a… |
|
CVE-2018-8174
HIGH 7.5
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution … |
|
CVE-2018-0824
HIGH 7.5
Microsoft COM for Windows Remote Code Execution Vulnerability |
|
CVE-2017-8464
CRITICAL 7.5
LNK Remote Code Execution Vulnerability |
|
CVE-2017-0263
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2017-0213
HIGH 6.7
Windows COM Elevation of Privilege Vulnerability |
|
CVE-2017-0145
HIGH 8.8
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.… |
|
CVE-2017-0144
HIGH 8.8
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.… |
|
CVE-2017-0148
CRITICAL 8.1
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0147
HIGH 8.1
Windows SMB Information Disclosure Vulnerability |
|
CVE-2017-0146
CRITICAL 8.1
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0143
CRITICAL 8.1
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2016-7255
HIGH 6.1
Win32k Elevation of Privilege Vulnerability |
|
CVE-2016-3309
HIGH
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2016-0165
HIGH 7.8
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows… |
|
CVE-2016-0151
HIGH 7.8
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages… |
|
CVE-2013-1690
HIGH 8.8
1 app
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadyst… |
|
CVE-2010-3765
CRITICAL 9.8
1 app
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when Ja… |