CISA KEV
Actively exploited vulnerabilities (CISA KEV)
285 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-24201
CRITICAL 10.0
KEV
Network
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15… |
|
CVE-2025-26633
HIGH 7.0
KEV
Local
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-24993
HIGH 7.8
KEV
Windows NTFS Remote Code Execution Vulnerability |
|
CVE-2025-24991
HIGH 5.5
KEV
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24985
HIGH 7.8
KEV
Windows Fast FAT File System Driver Remote Code Execution Vulnerability |
|
CVE-2025-24984
HIGH 4.6
KEV
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24983
HIGH 7.0
KEV
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-24054
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2024-50302
MEDIUM 5.5
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-43093
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-21418
HIGH 7.8
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-21391
HIGH 7.1
KEV
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2025-24200
MEDIUM 6.1
KEV
Physical
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 1… |
|
CVE-2024-53104
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-24085
CRITICAL 10.0
KEV
Network
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS… |
|
CVE-2025-0411
HIGH 7.0
KEV
Local 1 apps
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installat… |
|
CVE-2025-21335
HIGH 7.8
KEV
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2025-21334
HIGH 7.8
KEV
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2025-21333
HIGH 7.8
KEV
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
|
CVE-2024-49138
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2024-44309
MEDIUM 6.3
KEV
Network
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPad… |
|
CVE-2024-44308
HIGH 8.8
KEV
Network
The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 1… |
|
CVE-2024-49039
HIGH 8.8
KEV
Local
Windows Task Scheduler Elevation of Privilege Vulnerability |
|
CVE-2024-43451
HIGH 6.5
KEV
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2024-43047
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-9680
CRITICAL 9.8
KEV
Network 1 apps
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner… |
|
CVE-2024-43573
MEDIUM 6.5
KEV
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-43572
HIGH 7.8
KEV
Microsoft Management Console Remote Code Execution Vulnerability |
|
CVE-2024-43461
HIGH 8.8
KEV
Network
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-38217
MEDIUM 5.4
KEV
Network
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-38014
HIGH 7.8
KEV
Local
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2024-32896
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-38213
MEDIUM 6.5
KEV
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-38193
HIGH 7.8
KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2024-38178
HIGH 7.5
KEV
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2024-38107
HIGH 7.8
KEV
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability |
|
CVE-2024-38106
HIGH 7.0
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-36971
HIGH 7.8
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-38112
HIGH 7.5
KEV
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-38080
HIGH 7.8
KEV
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2024-39891
MEDIUM 5.3
KEV
Network 2 apps
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-numb… |
|
CVE-2024-4610
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2024-35250
HIGH 7.8
KEV
Local
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
|
CVE-2024-30088
HIGH 7.0
KEV
Local
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-30051
HIGH 7.8
KEV
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2024-30040
HIGH 8.8
KEV
Windows MSHTML Platform Security Feature Bypass Vulnerability |
|
CVE-2024-29988
HIGH 8.8
KEV
SmartScreen Prompt Security Feature Bypass Vulnerability |
|
CVE-2024-26169
HIGH 7.8
KEV
Windows Error Reporting Service Elevation of Privilege Vulnerability |
|
CVE-2024-23296
HIGH 7.8
KEV
Local
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey… |
|
CVE-2024-23225
HIGH 7.8
KEV
Local
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey… |