CISA KEV
Actively exploited vulnerabilities (CISA KEV)
22 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-21525
MEDIUM 6.2
KEV
Windows Remote Access Connection Manager Denial of Service Vulnerability |
|
CVE-2026-20805
MEDIUM 5.5
KEV
Local
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. |
|
CVE-2025-43520
MEDIUM 5.5
KEV
Local
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Seq… |
|
CVE-2025-55177
MEDIUM 5.4
KEV
Network 1 apps
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsAp… |
|
CVE-2025-43200
MEDIUM 4.2
KEV
Network
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.… |
|
CVE-2024-50302
MEDIUM 5.5
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-24200
MEDIUM 6.1
KEV
Physical
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 1… |
|
CVE-2024-44309
MEDIUM 6.3
KEV
Network
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPad… |
|
CVE-2024-43573
MEDIUM 6.5
KEV
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-38217
MEDIUM 5.4
KEV
Network
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-38213
MEDIUM 6.5
KEV
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-39891
MEDIUM 5.3
KEV
Network 2 apps
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-numb… |
|
CVE-2023-42916
MEDIUM 6.5
KEV
Network
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Pr… |
|
CVE-2023-26083
MEDIUM
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-24880
MEDIUM 4.4
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-44698
MEDIUM 5.4
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-41091
MEDIUM 5.4
KEV
Network
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2022-41049
MEDIUM 5.4
KEV
Network
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2013-3900
MEDIUM 5.5
KEV
WinVerifyTrust Signature Validation Vulnerability |
|
CVE-2021-34448
MEDIUM 6.8
KEV
Network
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-1906
MEDIUM
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2013-1675
MEDIUM 6.5
KEV
Network 1 apps
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data … |