CISA KEV
Actively exploited vulnerabilities (CISA KEV)
212 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-38178
HIGH 7.5
KEV
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2024-38107
HIGH 7.8
KEV
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability |
|
CVE-2024-38106
HIGH 7.0
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-38112
HIGH 7.5
KEV
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-38080
HIGH 7.8
KEV
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2024-35250
HIGH 7.8
KEV
Local
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
|
CVE-2024-30088
HIGH 7.0
KEV
Local
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-30051
HIGH 7.8
KEV
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2024-30040
HIGH 8.8
KEV
Windows MSHTML Platform Security Feature Bypass Vulnerability |
|
CVE-2024-29988
HIGH 8.8
KEV
SmartScreen Prompt Security Feature Bypass Vulnerability |
|
CVE-2024-26169
HIGH 7.8
KEV
Windows Error Reporting Service Elevation of Privilege Vulnerability |
|
CVE-2024-21412
HIGH 8.1
KEV
Network
Internet Shortcut Files Security Feature Bypass Vulnerability |
|
CVE-2024-21351
HIGH 7.6
KEV
Network
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2024-21338
HIGH 7.8
KEV
Local
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-36424
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36036
HIGH 7.8
KEV
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36033
HIGH 7.8
KEV
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2023-36025
HIGH 8.8
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-44487
HIGH 7.5
KEV
Network
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w… |
|
CVE-2023-36584
HIGH 5.4
KEV
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2023-36563
HIGH 6.5
KEV
Microsoft WordPad Information Disclosure Vulnerability |
|
CVE-2023-5217
HIGH 8.8
KEV
Network 2 apps
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap… |
|
CVE-2023-4863
HIGH 8.8
KEV
Network 1 apps
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write v… |
|
CVE-2023-36802
HIGH 7.8
KEV
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability |
|
CVE-2023-38831
HIGH 7.8
KEV
Local 1 apps
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because … |
|
CVE-2023-36884
HIGH 7.5
KEV
Network
Windows Search Remote Code Execution Vulnerability |
|
CVE-2023-36874
HIGH 7.8
KEV
Windows Error Reporting Service Elevation of Privilege Vulnerability |
|
CVE-2023-32049
HIGH 8.8
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-32046
HIGH 7.8
KEV
Windows MSHTML Platform Elevation of Privilege Vulnerability |
|
CVE-2023-29360
HIGH 8.4
KEV
Microsoft Streaming Service Elevation of Privilege Vulnerability |
|
CVE-2023-29336
HIGH 7.8
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-28252
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-28229
HIGH 7.0
KEV
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |
|
CVE-2023-24880
MEDIUM 4.4
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-23376
HIGH 7.8
KEV
Local
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-21823
HIGH 7.8
KEV
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2023-21674
HIGH 8.8
KEV
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability |
|
CVE-2022-44698
MEDIUM 5.4
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-41128
HIGH 8.8
KEV
Network
Windows Scripting Languages Remote Code Execution Vulnerability |
|
CVE-2022-41125
HIGH 7.8
KEV
Local
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |
|
CVE-2022-41091
MEDIUM 5.4
KEV
Network
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2022-41073
HIGH 7.8
KEV
Local
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-41049
MEDIUM 5.4
KEV
Network
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2022-41033
HIGH 7.8
KEV
Windows COM+ Event System Service Elevation of Privilege Vulnerability |
|
CVE-2022-38028
HIGH 7.8
KEV
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-37969
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2022-34713
HIGH 7.8
KEV
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability |
|
CVE-2022-22047
HIGH 7.8
KEV
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability |
|
CVE-2022-30190
HIGH 7.8
KEV
Local
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully e… |
|
CVE-2022-26925
HIGH 8.1
KEV
Windows LSA Spoofing Vulnerability |