Skip to content
Appaloosa Scout

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

212 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2024-38178
HIGH 7.5 KEV

Scripting Engine Memory Corruption Vulnerability

CVE-2024-38107
HIGH 7.8 KEV

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

CVE-2024-38106
HIGH 7.0 KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-38112
HIGH 7.5 KEV

Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-38080
HIGH 7.8 KEV

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2024-35250
HIGH 7.8 KEV Local

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

CVE-2024-30088
HIGH 7.0 KEV Local

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-30051
HIGH 7.8 KEV

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2024-30040
HIGH 8.8 KEV

Windows MSHTML Platform Security Feature Bypass Vulnerability

CVE-2024-29988
HIGH 8.8 KEV

SmartScreen Prompt Security Feature Bypass Vulnerability

CVE-2024-26169
HIGH 7.8 KEV

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2024-21412
HIGH 8.1 KEV Network

Internet Shortcut Files Security Feature Bypass Vulnerability

CVE-2024-21351
HIGH 7.6 KEV Network

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2024-21338
HIGH 7.8 KEV Local

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-36424
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-36036
HIGH 7.8 KEV

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-36033
HIGH 7.8 KEV

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2023-36025
HIGH 8.8 KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2023-44487
HIGH 7.5 KEV Network

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w…

CVE-2023-36584
HIGH 5.4 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2023-36563
HIGH 6.5 KEV

Microsoft WordPad Information Disclosure Vulnerability

CVE-2023-5217
HIGH 8.8 KEV Network 2 apps

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap…

CVE-2023-4863
HIGH 8.8 KEV Network 1 apps

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write v…

CVE-2023-36802
HIGH 7.8 KEV

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CVE-2023-38831
HIGH 7.8 KEV Local 1 apps

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because …

CVE-2023-36884
HIGH 7.5 KEV Network

Windows Search Remote Code Execution Vulnerability

CVE-2023-36874
HIGH 7.8 KEV

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2023-32049
HIGH 8.8 KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2023-32046
HIGH 7.8 KEV

Windows MSHTML Platform Elevation of Privilege Vulnerability

CVE-2023-29360
HIGH 8.4 KEV

Microsoft Streaming Service Elevation of Privilege Vulnerability

CVE-2023-29336
HIGH 7.8 KEV

Win32k Elevation of Privilege Vulnerability

CVE-2023-28252
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-28229
HIGH 7.0 KEV

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVE-2023-24880
MEDIUM 4.4 KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2023-23376
HIGH 7.8 KEV Local

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-21823
HIGH 7.8 KEV

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2023-21674
HIGH 8.8 KEV

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

CVE-2022-44698
MEDIUM 5.4 KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2022-41128
HIGH 8.8 KEV Network

Windows Scripting Languages Remote Code Execution Vulnerability

CVE-2022-41125
HIGH 7.8 KEV Local

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVE-2022-41091
MEDIUM 5.4 KEV Network

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2022-41073
HIGH 7.8 KEV Local

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-41049
MEDIUM 5.4 KEV Network

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2022-41033
HIGH 7.8 KEV

Windows COM+ Event System Service Elevation of Privilege Vulnerability

CVE-2022-38028
HIGH 7.8 KEV

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-37969
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2022-34713
HIGH 7.8 KEV

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

CVE-2022-22047
HIGH 7.8 KEV

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

CVE-2022-30190
HIGH 7.8 KEV Local

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully e…

CVE-2022-26925
HIGH 8.1 KEV

Windows LSA Spoofing Vulnerability