Skip to content
Appaloosa Scout
Language selector
fr en

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

41 actively exploited CVEs (High, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.

Matching CVEs
41
Actively exploited
229
Publication window
2013-06-26 → 2025-06-10

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

41 entries High CISA KEV Public exploit Clear all
CVE
CVE-2025-33073
HIGH 8.8

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2025-30397
HIGH 7.5

Scripting Engine Memory Corruption Vulnerability

CVE-2025-26633
HIGH 7.0

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-24054
HIGH 6.5

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-21333
HIGH 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2024-49138
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2024-38193
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2024-21338
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-44487
HIGH 7.5

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w…

CVE-2023-29336
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2022-0847
HIGH 7.8

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2019-17026
HIGH 8.8 1 app

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild a…

CVE-2020-0683
HIGH 7.0

Windows Installer Elevation of Privilege Vulnerability

CVE-2019-18426
HIGH 8.2 1 app

A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and l…

CVE-2020-0601
HIGH 8.1

Windows CryptoAPI Spoofing Vulnerability

CVE-2019-1458
HIGH 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privil…

CVE-2019-1405
HIGH 7.8

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP…

CVE-2019-1322
HIGH 7.0

Microsoft Windows Elevation of Privilege Vulnerability

CVE-2019-2215
HIGH

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2019-1253
HIGH 7.8

Windows Elevation of Privilege Vulnerability

CVE-2019-1215
HIGH 7.8

Windows Elevation of Privilege Vulnerability

CVE-2019-11707
HIGH 8.8 1 app

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware…

CVE-2019-0863
HIGH 7.8

Windows Error Reporting Elevation of Privilege Vulnerability

CVE-2019-0841
HIGH 6.8

Windows Elevation of Privilege Vulnerability

CVE-2019-0803
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2018-20250
HIGH 7.8 1 app

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When…

CVE-2019-0543
HIGH 7.8

Microsoft Windows Elevation of Privilege Vulnerability

CVE-2018-8453
HIGH 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privil…

CVE-2016-9079
HIGH 7.5 1 app

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a…

CVE-2018-8174
HIGH 7.5

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution …

CVE-2018-0824
HIGH 7.5

Microsoft COM for Windows Remote Code Execution Vulnerability

CVE-2017-0263
HIGH 7.8

Win32k Elevation of Privilege Vulnerability

CVE-2017-0213
HIGH 6.7

Windows COM Elevation of Privilege Vulnerability

CVE-2017-0145
HIGH 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.…

CVE-2017-0144
HIGH 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.…

CVE-2017-0147
HIGH 8.1

Windows SMB Information Disclosure Vulnerability

CVE-2016-7255
HIGH 6.1

Win32k Elevation of Privilege Vulnerability

CVE-2016-3309
HIGH

Windows Kernel Elevation of Privilege Vulnerability

CVE-2016-0165
HIGH 7.8

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows…

CVE-2016-0151
HIGH 7.8

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages…

CVE-2013-1690
HIGH 8.8 1 app

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadyst…