CISA KEV
Actively exploited vulnerabilities (CISA KEV)
21 actively exploited CVEs (Medium, Windows) affect a tracked app or OS. CISA confirms exploitation in the wild for each one.
- Matching CVEs
- 21
- Actively exploited
- 21
- Publication window
- 2013-05-16 → 2026-04-14
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2026-32202
MEDIUM 4.3
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-21525
MEDIUM · vendor
Windows Remote Access Connection Manager Denial of Service Vulnerability |
|
CVE-2026-20805
MEDIUM 5.5
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. |
|
CVE-2024-43573
MEDIUM · vendor
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-38217
MEDIUM 5.4
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-38213
MEDIUM · vendor
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2023-36761
Microsoft Word Information Disclosure Vulnerability |
|
CVE-2023-24880
MEDIUM · vendor
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-44698
MEDIUM · vendor
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-41091
MEDIUM 5.4
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2022-41049
MEDIUM 5.4
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2022-2856
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a … |
|
CVE-2013-3900
MEDIUM · vendor
WinVerifyTrust Signature Validation Vulnerability |
|
CVE-2021-38000
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a m… |
|
CVE-2021-41379
MEDIUM 5.5
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2021-37976
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from proces… |
|
CVE-2021-34448
MEDIUM 6.8
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-30533
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafte… |
|
CVE-2020-0878
MEDIUM 4.2
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way th… |
|
CVE-2016-3351
MEDIUM 6.5
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Brows… |
|
CVE-2013-1675
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data … |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.