Skip to content
Appaloosa Scout
Language selector
fr en

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

372 actively exploited CVEs (all severities, all platforms) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.

Matching CVEs
372
Actively exploited
372
Publication window
2007-02-03 → 2026-09-09

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

372 entries CISA KEV Clear all
CVE
CVE-2025-6558
HIGH 8.8

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox…

CVE-2025-48384
HIGH 8.0

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to int…

CVE-2025-6554
HIGH 8.1

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium secur…

CVE-2025-6218
HIGH 7.8

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install…

CVE-2025-43200
MEDIUM 4.2

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.…

CVE-2025-33073
HIGH · vendor

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2025-33053
HIGH · vendor

Internet Shortcut Files Remote Code Execution Vulnerability

CVE-2025-5419
HIGH 8.8

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

CVE-2025-32709
HIGH · vendor

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-32706
HIGH · vendor

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-32701
HIGH · vendor

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-30400
HIGH · vendor

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-30397
HIGH · vendor

Scripting Engine Memory Corruption Vulnerability

CVE-2025-27363
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-31201
CRITICAL 9.8

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.…

CVE-2025-31200
CRITICAL 9.8

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, …

CVE-2025-29824
HIGH · vendor

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2024-53197
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-53150
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-2783
HIGH 8.3

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandb…

CVE-2025-24201
CRITICAL 10.0

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15…

CVE-2025-26633
HIGH 7.0

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-24993
HIGH 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2025-24991
HIGH · vendor

Windows NTFS Information Disclosure Vulnerability

CVE-2025-24985
HIGH · vendor

Windows Fast FAT File System Driver Remote Code Execution Vulnerability

CVE-2025-24984
HIGH · vendor

Windows NTFS Information Disclosure Vulnerability

CVE-2025-24983
HIGH · vendor

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVE-2025-24054
HIGH · vendor

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-50302
MEDIUM · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-43093
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-21391
HIGH 7.1

Windows Storage Elevation of Privilege Vulnerability

CVE-2025-21418
HIGH · vendor

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-24200
MEDIUM 6.1

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 1…

CVE-2024-53104
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2025-24085
CRITICAL 10.0

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS…

CVE-2025-0411
HIGH 7.0

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installat…

CVE-2025-21335
HIGH 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2025-21334
HIGH · vendor

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2025-21333
HIGH · vendor

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2024-49138
HIGH · vendor

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2024-44309
MEDIUM 6.3

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPad…

CVE-2024-44308
HIGH 8.8

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 1…

CVE-2024-49039
HIGH 8.8

Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2024-43451
HIGH · vendor

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-43047
HIGH · vendor

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2024-9680
CRITICAL 9.8

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner…

CVE-2024-43573
MEDIUM · vendor

Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-43572
HIGH · vendor

Microsoft Management Console Remote Code Execution Vulnerability

CVE-2024-43461
HIGH 8.8

Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-38226
HIGH 7.3

Microsoft Publisher Security Feature Bypass Vulnerability

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM