KEV CISA
Vulnérabilités activement exploitées (KEV CISA)
37 CVE activement exploitées (Critique, Windows) touchent une app ou un OS suivi. La CISA confirme leur exploitation pour chacune.
- CVE correspondantes
- 37
- Activement exploitées
- 37
- Fenêtre de publication
- 2010-10-28 → 2026-04-14
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-33824
CRITICAL 9.8
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
|
CVE-2025-59287
CRITICAL · éditeur
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
|
CVE-2025-10585
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2024-9680
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner… |
|
CVE-2024-7971
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security s… |
|
CVE-2024-5274
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch… |
|
CVE-2024-4947
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chr… |
|
CVE-2024-4671
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a … |
|
CVE-2024-21413
Microsoft Outlook Remote Code Execution Vulnerability |
|
CVE-2023-6345
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a s… |
|
CVE-2023-2136
CRITICAL 9.6
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a s… |
|
CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability |
|
CVE-2022-4135
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform … |
|
CVE-2022-3075
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially… |
|
CVE-2022-26923
CRITICAL · éditeur
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-37973
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sa… |
|
CVE-2021-30633
Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perfo… |
|
CVE-2021-33742
CRITICAL · éditeur
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-31166
CRITICAL · éditeur
HTTP Protocol Stack Remote Code Execution Vulnerability |
|
CVE-2020-15999
CRITICAL 9.6
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… |
|
CVE-2020-1472
CRITICAL · éditeur
Netlogon Elevation of Privilege Vulnerability |
|
CVE-2020-1350
CRITICAL · éditeur
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2020-1040
CRITICAL · éditeur
Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability |
|
CVE-2020-1020
CRITICAL · éditeur
Adobe Font Manager Library Remote Code Execution Vulnerability |
|
CVE-2020-0938
CRITICAL · éditeur
Adobe Font Manager Library Remote Code Execution Vulnerability |
|
CVE-2020-0796
CRITICAL 10.0
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S… |
|
CVE-2019-11708
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op… |
|
CVE-2019-0903
CRITICAL · éditeur
GDI+ Remote Code Execution Vulnerability |
|
CVE-2017-8543
CRITICAL · éditeur
Windows Search Remote Code Execution Vulnerability |
|
CVE-2017-8464
CRITICAL · éditeur
LNK Remote Code Execution Vulnerability |
|
CVE-2017-0148
CRITICAL · éditeur
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0146
CRITICAL · éditeur
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0143
CRITICAL · éditeur
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2016-7256
CRITICAL · éditeur
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2016-3393
CRITICAL · éditeur
GDI+ Remote Code Execution Vulnerability |
|
CVE-2014-0497
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linu… |
|
CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when Ja… |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.