Skip to content
Appaloosa Scout

CISA KEV

Actively exploited vulnerabilities (CISA KEV)

212 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-56155
HIGH 7.8 KEV Local

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVE-2026-32202
HIGH 4.3 KEV

Windows Shell Spoofing Vulnerability

CVE-2026-21533
HIGH 7.8 KEV

Windows Remote Desktop Services Elevation of Privilege Vulnerability

CVE-2026-21525
MEDIUM 6.2 KEV

Windows Remote Access Connection Manager Denial of Service Vulnerability

CVE-2026-21519
HIGH 7.8 KEV

Desktop Window Manager Elevation of Privilege Vulnerability

CVE-2026-21513
HIGH 8.8 KEV

MSHTML Framework Security Feature Bypass Vulnerability

CVE-2026-21510
HIGH 8.8 KEV

Windows Shell Security Feature Bypass Vulnerability

CVE-2026-20805
MEDIUM 5.5 KEV Local

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

CVE-2025-62221
HIGH 7.8 KEV

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2025-62215
HIGH 7.0 KEV

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-60710
HIGH 7.8 KEV

Host Process for Windows Tasks Elevation of Privilege Vulnerability

CVE-2025-59287
CRITICAL 9.8 KEV

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2025-59230
HIGH 7.8 KEV

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-47827
HIGH 4.6 KEV

MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11

CVE-2025-24990
HIGH 7.8 KEV

Windows Agere Modem Driver Elevation of Privilege Vulnerability

CVE-2025-8088
HIGH 8.8 KEV Network 1 apps

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This…

CVE-2025-48384
HIGH 8.0 KEV Network 2 apps

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to int…

CVE-2025-6218
HIGH 7.8 KEV Local 1 apps

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install…

CVE-2025-33073
HIGH 8.8 KEV

Windows SMB Client Elevation of Privilege Vulnerability

CVE-2025-33053
HIGH 8.8 KEV

Internet Shortcut Files Remote Code Execution Vulnerability

CVE-2025-32709
HIGH 7.8 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-32706
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-32701
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-30400
HIGH 7.8 KEV

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-30397
HIGH 7.5 KEV

Scripting Engine Memory Corruption Vulnerability

CVE-2025-29824
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-26633
HIGH 7.0 KEV Local

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

CVE-2025-24993
HIGH 7.8 KEV

Windows NTFS Remote Code Execution Vulnerability

CVE-2025-24991
HIGH 5.5 KEV

Windows NTFS Information Disclosure Vulnerability

CVE-2025-24985
HIGH 7.8 KEV

Windows Fast FAT File System Driver Remote Code Execution Vulnerability

CVE-2025-24984
HIGH 4.6 KEV

Windows NTFS Information Disclosure Vulnerability

CVE-2025-24983
HIGH 7.0 KEV

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVE-2025-24054
HIGH 6.5 KEV

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-21418
HIGH 7.8 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-21391
HIGH 7.1 KEV

Windows Storage Elevation of Privilege Vulnerability

CVE-2025-0411
HIGH 7.0 KEV Local 1 apps

7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installat…

CVE-2025-21335
HIGH 7.8 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2025-21334
HIGH 7.8 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2025-21333
HIGH 7.8 KEV

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

CVE-2024-49138
HIGH 7.8 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2024-49039
HIGH 8.8 KEV Local

Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2024-43451
HIGH 6.5 KEV

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-9680
CRITICAL 9.8 KEV Network 1 apps

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner…

CVE-2024-43573
MEDIUM 6.5 KEV

Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-43572
HIGH 7.8 KEV

Microsoft Management Console Remote Code Execution Vulnerability

CVE-2024-43461
HIGH 8.8 KEV Network

Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-38217
MEDIUM 5.4 KEV Network

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-38014
HIGH 7.8 KEV Local

Windows Installer Elevation of Privilege Vulnerability

CVE-2024-38213
MEDIUM 6.5 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-38193
HIGH 7.8 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability