Skip to content
Appaloosa Scout

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

22 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-21525
MEDIUM 6.2 KEV

Windows Remote Access Connection Manager Denial of Service Vulnerability

CVE-2026-20805
MEDIUM 5.5 KEV Local

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

CVE-2025-43520
MEDIUM 5.5 KEV Local

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Seq…

CVE-2025-55177
MEDIUM 5.4 KEV Network 1 apps

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsAp…

CVE-2025-43200
MEDIUM 4.2 KEV Network

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.…

CVE-2024-50302
MEDIUM 5.5 KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-24200
MEDIUM 6.1 KEV Physical

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 1…

CVE-2024-44309
MEDIUM 6.3 KEV Network

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPad…

CVE-2024-43573
MEDIUM 6.5 KEV

Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-38217
MEDIUM 5.4 KEV Network

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-38213
MEDIUM 6.5 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-39891
MEDIUM 5.3 KEV Network 2 apps

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-numb…

CVE-2023-42916
MEDIUM 6.5 KEV Network

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Pr…

CVE-2023-26083
MEDIUM KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-24880
MEDIUM 4.4 KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2022-44698
MEDIUM 5.4 KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2022-41091
MEDIUM 5.4 KEV Network

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2022-41049
MEDIUM 5.4 KEV Network

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2013-3900
MEDIUM 5.5 KEV

WinVerifyTrust Signature Validation Vulnerability

CVE-2021-34448
MEDIUM 6.8 KEV Network

Scripting Engine Memory Corruption Vulnerability

CVE-2021-1906
MEDIUM KEV

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2013-1675
MEDIUM 6.5 KEV Network 1 apps

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data …