Skip to content
Appaloosa Scout

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

227 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-56155
HIGH 7.8 KEV Local

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVE-2025-48595
HIGH 8.4 KEV Local

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no a…

CVE-2026-32202
HIGH 4.3 KEV

Windows Shell Spoofing Vulnerability

CVE-2026-21385
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2026-20700
HIGH 7.8 KEV Local

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS …

CVE-2026-21533
HIGH 7.8 KEV

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-21519
HIGH 7.8 KEV

Desktop Window Manager Elevation of Privilege Vulnerability

CVE-2026-21513
HIGH 8.8 KEV

MSHTML Framework Security Feature Bypass Vulnerability

CVE-2026-21510
HIGH 8.8 KEV

Windows Shell Security Feature Bypass Vulnerability

CVE-2025-43529
HIGH 8.8 KEV Network

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.…

CVE-2025-43510
HIGH 7.8 KEV Local

A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS…

CVE-2025-14174
HIGH 8.8 KEV Network

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a cra…

CVE-2025-62221
HIGH 7.8 KEV

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-48633
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-48572
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-62215
HIGH 7.0 KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-60710
HIGH 7.8 KEV

Host Process for Windows Tasks Elevation of Privilege Vulnerability

CVE-2023-43000
HIGH 8.8 KEV Network

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.…

CVE-2025-59230
HIGH 7.8 KEV

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-47827
HIGH 4.6 KEV

MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11

CVE-2025-24990
HIGH 7.8 KEV

Windows Agere Modem Driver Elevation of Privilege Vulnerability

CVE-2025-48543
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-8088
HIGH 8.8 KEV Network 1 apps

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This…

CVE-2025-27038
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-31277
HIGH 8.8 KEV Network

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.…

CVE-2025-38352
HIGH 7.8 KEV Local

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If…

CVE-2025-6558
HIGH 8.8 KEV Network

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox…

CVE-2025-48384
HIGH 8.0 KEV Network 2 apps

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to int…

CVE-2025-6218
HIGH 7.8 KEV Local 1 apps

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install…

CVE-2025-33073
HIGH 8.8 KEV

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2025-33053
HIGH 8.8 KEV

Internet Shortcut Files Remote Code Execution Vulnerability

CVE-2025-32709
HIGH 7.8 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-32706
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-32701
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-30400
HIGH 7.8 KEV

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-30397
HIGH 7.5 KEV

Scripting Engine Memory Corruption Vulnerability

CVE-2025-27363
HIGH 8.1 KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-29824
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2024-53197
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-53150
HIGH 7.8 KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-26633
HIGH 7.0 KEV Local

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-24993
HIGH 7.8 KEV

Windows NTFS Remote Code Execution Vulnerability

CVE-2025-24991
HIGH 5.5 KEV

Windows NTFS Information Disclosure Vulnerability

CVE-2025-24985
HIGH 7.8 KEV

Windows Fast FAT File System Driver Remote Code Execution Vulnerability

CVE-2025-24984
HIGH 4.6 KEV

Windows NTFS Information Disclosure Vulnerability

CVE-2025-24983
HIGH 7.0 KEV

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVE-2025-24054
HIGH 6.5 KEV

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-43093
HIGH KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-21418
HIGH 7.8 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-21391
HIGH 7.1 KEV

Windows Storage Elevation of Privilege Vulnerability