CISA KEV
Actively exploited vulnerabilities (CISA KEV)
36 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2025-59287
CRITICAL 9.8
KEV
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
|
CVE-2025-43300
CRITICAL 10.0
KEV
Network
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, … |
|
CVE-2025-21479
CRITICAL
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2025-31201
CRITICAL 9.8
KEV
Network
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.… |
|
CVE-2025-31200
CRITICAL 9.8
KEV
Network
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, … |
|
CVE-2025-24201
CRITICAL 10.0
KEV
Network
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15… |
|
CVE-2025-24085
CRITICAL 10.0
KEV
Network
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS… |
|
CVE-2024-9680
CRITICAL 9.8
KEV
Network 1 apps
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner… |
|
CVE-2023-2136
CRITICAL 9.6
KEV
Network
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a s… |
|
CVE-2022-26486
CRITICAL 9.6
KEV
Network 1 apps
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abu… |
|
CVE-2022-26923
CRITICAL 8.8
KEV
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-44228
CRITICAL 10.0
KEV
Network 1 apps
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter… |
|
CVE-2021-33742
CRITICAL 7.5
KEV
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-1675
CRITICAL 7.8
KEV
Windows Print Spooler Remote Code Execution Vulnerability |
|
CVE-2021-31166
CRITICAL 9.8
KEV
HTTP Protocol Stack Remote Code Execution Vulnerability |
|
CVE-2020-15999
CRITICAL 9.6
KEV
Network
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pa… |
|
CVE-2020-1472
CRITICAL 10.0
KEV
Netlogon Elevation of Privilege Vulnerability |
|
CVE-2020-1350
CRITICAL 10.0
KEV
Windows DNS Server Remote Code Execution Vulnerability |
|
CVE-2020-1040
CRITICAL 8.0
KEV
Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability |
|
CVE-2020-1020
CRITICAL 7.8
KEV
Adobe Font Manager Library Remote Code Execution Vulnerability |
|
CVE-2020-0938
CRITICAL 7.8
KEV
Adobe Font Manager Library Remote Code Execution Vulnerability |
|
CVE-2020-0796
CRITICAL 10.0
KEV
Windows SMBv3 Client/Server Remote Code Execution Vulnerability |
|
CVE-2019-11708
CRITICAL 10.0
KEV
Network 1 apps
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op… |
|
CVE-2019-0903
CRITICAL 8.8
KEV
GDI+ Remote Code Execution Vulnerability |
|
CVE-2018-8174
CRITICAL 7.5
KEV
Windows VBScript Engine Remote Code Execution Vulnerability |
|
CVE-2017-8543
CRITICAL 8.1
KEV
Windows Search Remote Code Execution Vulnerability |
|
CVE-2017-8464
CRITICAL 7.5
KEV
LNK Remote Code Execution Vulnerability |
|
CVE-2017-0148
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0146
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0145
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0144
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0143
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2016-5195
CRITICAL
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2016-7256
CRITICAL 8.8
KEV
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2016-3393
CRITICAL 8.8
KEV
GDI+ Remote Code Execution Vulnerability |
|
CVE-2010-3765
CRITICAL 9.8
KEV
Network 1 apps
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when Ja… |