KEV CISA
Vulnérabilités activement exploitées (KEV CISA)
244 CVE activement exploitées (Élevé, Windows) touchent une app ou un OS suivi. La CISA confirme leur exploitation pour chacune.
- CVE correspondantes
- 244
- Activement exploitées
- 244
- Fenêtre de publication
- 2007-02-03 → 2026-09-09
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-87491
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML pag… |
|
CVE-2026-85880
HIGH 7.8
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-81963
HIGH · éditeur
Windows Update Stack Elevation of Privilege Vulnerability |
|
CVE-2026-85046
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (C… |
|
CVE-2026-68820
HIGH 7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-56155
HIGH 7.8
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-11645
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … |
|
CVE-2026-34621
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype… |
|
CVE-2026-5281
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code vi… |
|
CVE-2026-3910
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H… |
|
CVE-2026-3909
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (… |
|
CVE-2026-2441
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch… |
|
CVE-2026-21533
HIGH · éditeur
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
|
CVE-2026-21519
HIGH · éditeur
Desktop Window Manager Elevation of Privilege Vulnerability |
|
CVE-2026-21513
HIGH · éditeur
MSHTML Framework Security Feature Bypass Vulnerability |
|
CVE-2026-21510
HIGH · éditeur
Windows Shell Security Feature Bypass Vulnerability |
|
CVE-2026-21509
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-14174
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a cra… |
|
CVE-2025-62221
HIGH 7.8
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2025-13223
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2025-62215
HIGH · éditeur
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-60710
HIGH · éditeur
Host Process for Windows Tasks Elevation of Privilege Vulnerability |
|
CVE-2025-59230
HIGH · éditeur
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2025-47827
HIGH · éditeur
MITRE CVE-2025-47827: Secure Boot bypass in IGEL OS before 11 |
|
CVE-2025-24990
HIGH · éditeur
Windows Agere Modem Driver Elevation of Privilege Vulnerability |
|
CVE-2025-8088
HIGH 8.8
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This… |
|
CVE-2025-6558
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox… |
|
CVE-2025-6554
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium secur… |
|
CVE-2025-6218
HIGH 7.8
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install… |
|
CVE-2025-33073
HIGH · éditeur
Windows SMB Client Elevation of Privilege Vulnerability |
|
CVE-2025-33053
HIGH · éditeur
Internet Shortcut Files Remote Code Execution Vulnerability |
|
CVE-2025-5419
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML … |
|
CVE-2025-32709
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-32706
HIGH · éditeur
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-32701
HIGH · éditeur
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-30400
HIGH · éditeur
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-30397
HIGH · éditeur
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2025-29824
HIGH · éditeur
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-2783
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandb… |
|
CVE-2025-26633
HIGH 7.0
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2025-24993
HIGH 7.8
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. |
|
CVE-2025-24991
HIGH · éditeur
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24985
HIGH · éditeur
Windows Fast FAT File System Driver Remote Code Execution Vulnerability |
|
CVE-2025-24984
HIGH · éditeur
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2025-24983
HIGH · éditeur
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2025-24054
HIGH · éditeur
NTLM Hash Disclosure Spoofing Vulnerability |
|
CVE-2025-21391
HIGH 7.1
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2025-21418
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-0411
HIGH 7.0
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installat… |
|
CVE-2025-21335
HIGH 7.8
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.