CISA KEV
Actively exploited vulnerabilities (CISA KEV)
285 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2018-20250
HIGH 7.8
KEV
Local 1 apps
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When… |
|
CVE-2019-0543
HIGH 7.8
KEV
Microsoft Windows Elevation of Privilege Vulnerability |
|
CVE-2018-8639
HIGH 7.0
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2018-8611
HIGH 7.0
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8453
HIGH 7.0
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2018-8440
HIGH 7.8
KEV
Windows ALPC Elevation of Privilege Vulnerability |
|
CVE-2018-8414
HIGH 4.8
KEV
Windows Shell Remote Code Execution Vulnerability |
|
CVE-2018-8406
HIGH 7.0
KEV
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2018-8405
HIGH 7.0
KEV
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2016-9079
HIGH 7.5
KEV
Network 1 apps
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a… |
|
CVE-2018-8174
CRITICAL 7.5
KEV
Windows VBScript Engine Remote Code Execution Vulnerability |
|
CVE-2018-0824
HIGH 7.5
KEV
Microsoft COM for Windows Remote Code Execution Vulnerability |
|
CVE-2017-8543
CRITICAL 8.1
KEV
Windows Search Remote Code Execution Vulnerability |
|
CVE-2017-8464
CRITICAL 7.5
KEV
LNK Remote Code Execution Vulnerability |
|
CVE-2017-0263
HIGH 7.8
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2017-0213
HIGH 6.7
KEV
Windows COM Elevation of Privilege Vulnerability |
|
CVE-2017-0148
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0147
HIGH 8.1
KEV
Windows SMB Information Disclosure Vulnerability |
|
CVE-2017-0146
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0145
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0144
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0143
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0005
HIGH 7.0
KEV
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2017-0001
HIGH 7.8
KEV
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2016-5195
CRITICAL
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-7256
CRITICAL 8.8
KEV
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2016-7255
HIGH 6.1
KEV
Win32k Elevation of Privilege Vulnerability |
|
CVE-2016-3393
CRITICAL 8.8
KEV
GDI+ Remote Code Execution Vulnerability |
|
CVE-2016-3309
HIGH
KEV
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2016-0167
HIGH 7.8
KEV
Local
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows… |
|
CVE-2016-0165
HIGH 7.8
KEV
Local
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows… |
|
CVE-2016-0151
HIGH 7.8
KEV
Local
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages… |
|
CVE-2013-1690
HIGH 8.8
KEV
Network 1 apps
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadyst… |
|
CVE-2013-1675
MEDIUM 6.5
KEV
Network 1 apps
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data … |
|
CVE-2010-3765
CRITICAL 9.8
KEV
Network 1 apps
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when Ja… |