Full CISA KEV catalog

Every CVE the U.S. cybersecurity agency has ever flagged as actively exploited. Filter by category, sort by severity or exploit-likelihood, search by vendor or product.

Showing 241–270 of 531 CVEs · Page 9 of 18 30 per page
Added CVE Vendor / Product Name & description CVSS EPSS
Jun 8, 2022 CVE-2009-0557 Microsoft Office
endpoint m365 smb essential
Microsoft Office Object Record Corruption Vulnerability
Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.
86.4%
Jun 8, 2022 CVE-2009-0563 Microsoft Office
endpoint m365 smb essential
Microsoft Office Buffer Overflow Vulnerability
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.
79.9%
Jun 8, 2022 CVE-2010-2572 Microsoft PowerPoint
endpoint m365 smb essential
Microsoft PowerPoint Buffer Overflow Vulnerability
Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.
74.7%
Jun 8, 2022 CVE-2012-0151 Microsoft Windows
endpoint m365 smb essential
Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability
The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allow…
89.0%
Jun 8, 2022 CVE-2012-1889 Microsoft XML Core Services
endpoint m365 smb essential
Microsoft XML Core Services Memory Corruption Vulnerability
Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.
93.1%
Jun 8, 2022 CVE-2012-4969 Microsoft Internet Explorer
endpoint m365 smb essential
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site.
91.8%
Jun 8, 2022 CVE-2013-1331 Microsoft Office
endpoint m365 smb essential
Microsoft Office Buffer Overflow Vulnerability
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document.
88.9%
May 25, 2022 CVE-2013-0074
Ransomware
Microsoft Silverlight
endpoint m365 smb essential
Microsoft Silverlight Double Dereference Vulnerability
Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
93.7%
May 25, 2022 CVE-2013-3896 Microsoft Silverlight
endpoint m365 smb essential
Microsoft Silverlight Information Disclosure Vulnerability
Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silver…
84.7%
May 25, 2022 CVE-2013-7331 Microsoft Internet Explorer
endpoint m365 smb essential
Microsoft Internet Explorer Information Disclosure Vulnerability
An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect a…
81.8%
May 25, 2022 CVE-2014-2817 Microsoft Internet Explorer
endpoint m365 smb essential
Microsoft Internet Explorer Privilege Escalation Vulnerability
Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.
29.1%
May 25, 2022 CVE-2014-4077 Microsoft Input Method Editor (IME) Japanese
endpoint m365 smb essential
Microsoft IME Japanese Privilege Escalation Vulnerability
Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as di…
51.3%
May 25, 2022 CVE-2014-4123 Microsoft Internet Explorer
endpoint m365 smb essential
Microsoft Internet Explorer Privilege Escalation Vulnerability
Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.
39.8%
May 25, 2022 CVE-2014-4148 Microsoft Windows
endpoint m365 smb essential
Microsoft Windows Remote Code Execution Vulnerability
A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.
55.7%
May 25, 2022 CVE-2015-0016 Microsoft Windows
endpoint m365 smb essential
Microsoft Windows TS WebProxy Directory Traversal Vulnerability
Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
92.1%
May 25, 2022 CVE-2015-0071 Microsoft Internet Explorer
endpoint m365 smb essential
Microsoft Internet Explorer ASLR Bypass Vulnerability
Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site.
34.2%
May 25, 2022 CVE-2015-1671 Microsoft Windows
endpoint m365 smb essential
Microsoft Windows Remote Code Execution Vulnerability
A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
88.0%
May 25, 2022 CVE-2015-1769 Microsoft Windows
endpoint m365 smb essential
Microsoft Windows Mount Manager Privilege Escalation Vulnerability
A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.
57.4%
May 25, 2022 CVE-2015-2360 Microsoft Win32k
endpoint m365 smb essential
Microsoft Win32k Privilege Escalation Vulnerability
Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).
52.4%
May 25, 2022 CVE-2015-2425 Microsoft Internet Explorer
endpoint m365 smb essential
Microsoft Internet Explorer Memory Corruption Vulnerability
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
34.8%
May 25, 2022 CVE-2015-6175 Microsoft Windows
endpoint m365 smb essential
Microsoft Windows Kernel Privilege Escalation Vulnerability
The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.
4.8%
May 25, 2022 CVE-2016-0034
Ransomware
Microsoft Silverlight
endpoint m365 smb essential
Microsoft Silverlight Runtime Remote Code Execution Vulnerability
Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
54.9%
May 25, 2022 CVE-2016-3393 Microsoft Windows
endpoint m365 smb essential
Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability
A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could…
55.7%
May 25, 2022 CVE-2016-7256 Microsoft Windows
endpoint m365 smb essential
Microsoft Windows Open Type Font Remote Code Execution Vulnerability
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerab…
55.5%
May 24, 2022 CVE-2016-0162 Microsoft Internet Explorer
endpoint m365 smb essential
Microsoft Internet Explorer Information Disclosure Vulnerability
An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on th…
43.7%
May 24, 2022 CVE-2016-3298 Microsoft Internet Explorer
endpoint m365 smb essential
Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability
An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerab…
28.3%
May 24, 2022 CVE-2016-3351
Ransomware
Microsoft Internet Explorer and Edge
browser endpoint m365 smb essential
Microsoft Internet Explorer and Edge Information Disclosure Vulnerability
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker …
45.4%
May 24, 2022 CVE-2016-4655 Apple iOS
endpoint mobile smb essential
Apple iOS Information Disclosure Vulnerability
The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
82.1%
May 24, 2022 CVE-2016-4656 Apple iOS
endpoint mobile smb essential
Apple iOS Memory Corruption Vulnerability
A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.
65.3%
May 24, 2022 CVE-2016-4657 Apple iOS
browser endpoint mobile smb essential
Apple iOS Webkit Memory Corruption Vulnerability
Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerabil…
79.4%

Source: CISA KEV catalog. Severity (CVSS) and exploit-probability (EPSS) sync nightly from NVD and FIRST.