CISA Known Exploited Vulnerabilities
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2021-38648 | HIGH | 7.8 | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. | Sep 15, 2021 |
| CVE-2021-38649 | HIGH | 7.0 | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation. | Sep 15, 2021 |
| CVE-2021-34527 | HIGH | 8.8 | Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. | Jul 2, 2021 |
| CVE-2025-9242 | CRITICAL | 9.8 | WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code. | Sep 17, 2025 |
| CVE-2021-34484 | HIGH | 7.8 | Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation. | Aug 12, 2021 |
| CVE-2026-16232 | CRITICAL | 9.8 | Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. | Jul 22, 2026 |
| CVE-2021-38646 | HIGH | 7.8 | Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution. | Sep 15, 2021 |
| CVE-2021-34523 | CRITICAL | 9.0 | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. | Jul 14, 2021 |
| CVE-2021-34486 | HIGH | 7.8 | Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation. | Aug 12, 2021 |
| CVE-2021-34473 | CRITICAL | 9.1 | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. | Jul 14, 2021 |
| CVE-2021-34448 | MEDIUM | 6.8 | Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption. | Jul 16, 2021 |
| CVE-2021-33771 | HIGH | 7.8 | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Jul 14, 2021 |
| CVE-2021-33766 | HIGH | 7.3 | Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target. | Jul 14, 2021 |
| CVE-2021-31979 | HIGH | 7.8 | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Jul 14, 2021 |
| CVE-2021-31196 | HIGH | 7.2 | Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution. | Jul 14, 2021 |
| CVE-2024-43461 | HIGH | 8.8 | Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112. | Sep 10, 2024 |
| CVE-2024-38226 | HIGH | 7.3 | Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files. | Sep 10, 2024 |
| CVE-2024-38217 | MEDIUM | 5.4 | Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging. | Sep 10, 2024 |
| CVE-2024-38014 | HIGH | 7.8 | Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges. | Sep 10, 2024 |
| CVE-2024-21413 | CRITICAL | 9.8 | Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode. | Feb 13, 2024 |
| CVE-2024-21412 | HIGH | 8.1 | Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass. | Feb 13, 2024 |
| CVE-2024-21351 | HIGH | 7.6 | Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both. | Feb 13, 2024 |
| CVE-2024-21338 | HIGH | 7.8 | Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation. | Feb 13, 2024 |
| CVE-2023-38180 | HIGH | 7.5 | Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS). | Aug 8, 2023 |
| CVE-2023-36884 | HIGH | 7.5 | Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution. | Jul 11, 2023 |