CISA KEV
Actively exploited vulnerabilities (CISA KEV)
372 actively exploited CVEs (all severities, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.
- Matching CVEs
- 372
- Actively exploited
- 372
- Publication window
- 2007-02-03 → 2026-09-09
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-87491
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pag… |
|
CVE-2026-85880
HIGH 7.8
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-81963
HIGH · vendor
Windows Update Stack Elevation of Privilege Vulnerability |
|
CVE-2026-85046
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C… |
|
CVE-2026-68820
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-65400
CRITICAL 9.8
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, m… |
|
CVE-2026-56155
HIGH 7.8
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-11645
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … |
|
CVE-2025-48595
HIGH 8.4
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no a… |
|
CVE-2026-33824
CRITICAL 9.8
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
|
CVE-2026-32202
MEDIUM 4.3
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-34621
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype… |
|
CVE-2026-5281
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code vi… |
|
CVE-2026-3910
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H… |
|
CVE-2026-3909
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (… |
|
CVE-2026-21385
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2026-2441
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch… |
|
CVE-2026-20700
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS … |
|
CVE-2026-21533
HIGH · vendor
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
|
CVE-2026-21525
MEDIUM · vendor
Windows Remote Access Connection Manager Denial of Service Vulnerability |
|
CVE-2026-21519
HIGH · vendor
Desktop Window Manager Elevation of Privilege Vulnerability |
|
CVE-2026-21513
HIGH · vendor
MSHTML Framework Security Feature Bypass Vulnerability |
|
CVE-2026-21510
HIGH · vendor
Windows Shell Security Feature Bypass Vulnerability |
|
CVE-2026-21509
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2026-20805
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. |
|
CVE-2025-43529
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.… |
|
CVE-2025-43520
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Seq… |
|
CVE-2025-43510
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS… |
|
CVE-2025-14174
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a cra… |
|
CVE-2025-62221
HIGH 7.8
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2025-48633
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-48572
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-13223
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2025-62215
HIGH · vendor
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-60710
HIGH · vendor
Host Process for Windows Tasks Elevation of Privilege Vulnerability |
|
CVE-2023-43000
HIGH 8.8
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.… |
|
CVE-2025-59287
CRITICAL · vendor
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
|
CVE-2025-59230
HIGH · vendor
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2025-47827
HIGH · vendor
MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11 |
|
CVE-2025-24990
HIGH · vendor
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-10585
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2025-39682
CRITICAL 9.8
In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process … |
|
CVE-2025-48543
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-55177
MEDIUM 5.4
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsAp… |
|
CVE-2025-43300
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, … |
|
CVE-2025-8088
HIGH 8.8
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This… |
|
CVE-2025-27038
HIGH · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-21479
CRITICAL · vendor
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-31277
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.… |
|
CVE-2025-38352
HIGH 7.8
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If… |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.