CISA KEV
Actively exploited vulnerabilities (CISA KEV)
285 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2024-21412
HIGH 8.1
KEV
Network
Internet Shortcut Files Security Feature Bypass Vulnerability |
|
CVE-2024-21351
HIGH 7.6
KEV
Network
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2024-21338
HIGH 7.8
KEV
Local
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-23222
HIGH 8.8
KEV
Network
A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS … |
|
CVE-2023-41974
HIGH 7.8
KEV
Local
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be … |
|
CVE-2023-33107
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33106
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-33063
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-42917
HIGH 8.8
KEV
Network
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2.… |
|
CVE-2023-42916
MEDIUM 6.5
KEV
Network
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Pr… |
|
CVE-2023-36424
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36036
HIGH 7.8
KEV
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36033
HIGH 7.8
KEV
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2023-36025
HIGH 8.8
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-44487
HIGH 7.5
KEV
Network
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w… |
|
CVE-2023-36584
HIGH 5.4
KEV
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2023-36563
HIGH 6.5
KEV
Microsoft WordPad Information Disclosure Vulnerability |
|
CVE-2023-4211
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-5217
HIGH 8.8
KEV
Network 2 apps
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap… |
|
CVE-2023-4863
HIGH 8.8
KEV
Network 1 apps
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write v… |
|
CVE-2023-36802
HIGH 7.8
KEV
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability |
|
CVE-2023-35674
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-38831
HIGH 7.8
KEV
Local 1 apps
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because … |
|
CVE-2023-36884
HIGH 7.5
KEV
Network
Windows Search Remote Code Execution Vulnerability |
|
CVE-2023-36874
HIGH 7.8
KEV
Windows Error Reporting Service Elevation of Privilege Vulnerability |
|
CVE-2023-32049
HIGH 8.8
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-32046
HIGH 7.8
KEV
Windows MSHTML Platform Elevation of Privilege Vulnerability |
|
CVE-2023-26083
MEDIUM
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-29256
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-29360
HIGH 8.4
KEV
Microsoft Streaming Service Elevation of Privilege Vulnerability |
|
CVE-2022-22706
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-29336
HIGH 7.8
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-0266
HIGH 7.8
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-0847
HIGH 7.8
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-22600
HIGH 7.0
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-2136
CRITICAL 9.6
KEV
Network
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a s… |
|
CVE-2023-28252
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-28229
HIGH 7.0
KEV
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |
|
CVE-2022-38181
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-24880
MEDIUM 4.4
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-20963
HIGH
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2023-23376
HIGH 7.8
KEV
Local
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-21823
HIGH 7.8
KEV
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2023-21674
HIGH 8.8
KEV
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability |
|
CVE-2022-26486
CRITICAL 9.6
KEV
Network 1 apps
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abu… |
|
CVE-2022-26485
HIGH 8.8
KEV
Network 1 apps
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. Th… |
|
CVE-2022-44698
MEDIUM 5.4
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-41128
HIGH 8.8
KEV
Network
Windows Scripting Languages Remote Code Execution Vulnerability |
|
CVE-2022-41125
HIGH 7.8
KEV
Local
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |
|
CVE-2022-41091
MEDIUM 5.4
KEV
Network
Windows Mark of the Web Security Feature Bypass Vulnerability |