Skip to content
Appaloosa Scout

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

229 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2025-21391
HIGH 7.1 KEV

Windows Storage Elevation of Privilege Vulnerability

CVE-2024-53104
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-0411
HIGH 7.0 KEV Local 1 apps

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installat…

CVE-2025-21335
HIGH 7.8 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2025-21334
HIGH 7.8 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2025-21333
HIGH 7.8 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2024-49138
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2024-44308
HIGH 8.8 KEV Network

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 1…

CVE-2024-49039
HIGH 8.8 KEV Local

Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2024-43451
HIGH 6.5 KEV

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-43047
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-43572
HIGH 7.8 KEV

Microsoft Management Console Remote Code Execution Vulnerability

CVE-2024-43461
HIGH 8.8 KEV Network

Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-38014
HIGH 7.8 KEV Local

Windows Installer Elevation of Privilege Vulnerability

CVE-2024-32896
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-38193
HIGH 7.8 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2024-38178
HIGH 7.5 KEV

Scripting Engine Memory Corruption Vulnerability

CVE-2024-38107
HIGH 7.8 KEV

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

CVE-2024-38106
HIGH 7.0 KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-36971
HIGH 7.8 KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-38112
HIGH 7.5 KEV

Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-38080
HIGH 7.8 KEV

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2024-4610
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-35250
HIGH 7.8 KEV Local

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

CVE-2024-30088
HIGH 7.0 KEV Local

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-30051
HIGH 7.8 KEV

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2024-30040
HIGH 8.8 KEV

Windows MSHTML Platform Security Feature Bypass Vulnerability

CVE-2024-29988
HIGH 8.8 KEV

SmartScreen Prompt Security Feature Bypass Vulnerability

CVE-2024-26169
HIGH 7.8 KEV

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2024-23296
HIGH 7.8 KEV Local

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey…

CVE-2024-23225
HIGH 7.8 KEV Local

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey…

CVE-2024-21412
HIGH 8.1 KEV Network

Internet Shortcut Files Security Feature Bypass Vulnerability

CVE-2024-21351
HIGH 7.6 KEV Network

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2024-21338
HIGH 7.8 KEV Local

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-23222
HIGH 8.8 KEV Network

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS …

CVE-2023-41974
HIGH 7.8 KEV Local

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be …

CVE-2023-33107
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-33106
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-33063
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-42917
HIGH 8.8 KEV Network

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2.…

CVE-2023-36424
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-36036
HIGH 7.8 KEV

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-36033
HIGH 7.8 KEV

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2023-36025
HIGH 8.8 KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2023-44487
HIGH 7.5 KEV Network

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w…

CVE-2023-36584
HIGH 5.4 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2023-36563
HIGH 6.5 KEV

Microsoft WordPad Information Disclosure Vulnerability

CVE-2023-4211
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-5217
HIGH 8.8 KEV Network 2 apps

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap…

CVE-2023-4863
HIGH 8.8 KEV Network 1 apps

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write v…