KEVIntel
0.7%
actively
exploited

Focus on what’s exploited

Out of 350,131 known CVEs, only 0.7% show real-world exploitation signals.

Data from public sources (including CISA) plus private sensors, enriched with prioritization metadata.

2,501
Total Known exploited
353
Added this week

Search

Added
Exploitability

Type to search. Filters apply instantly.

CVE Severity Title
CVE-2019-1429 7.5 High
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...
Remote
CVE-2017-11774 7.8 High
Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft...
Low complexity
CVE-2020-0968 7.5 High
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting...
Remote
CVE-2020-1472 5.5 Medium
Netlogon Elevation of Privilege Vulnerability
Malware Low complexity No user interaction
CVE-2021-26855 9.1 Critical
Microsoft Exchange Server Remote Code Execution Vulnerability
Malware Remote Low complexity No user interaction
CVE-2021-26858 7.8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
Malware Low complexity
CVE-2021-27065 7.8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
Malware Low complexity
CVE-2020-1054 7.8 High
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka...
Low complexity No user interaction
CVE-2021-1675 7.8 High
Windows Print Spooler Remote Code Execution Vulnerability
Malware Low complexity
CVE-2021-34448 6.8 Medium
Scripting Engine Memory Corruption Vulnerability
Remote
CVE-2020-0601 8.1 High
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker...
Remote Low complexity
CVE-2019-0604 9.8 Critical
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package,...
Malware Remote Low complexity No user interaction
CVE-2020-0646 9.8 Critical
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code...
Remote Low complexity No user interaction
CVE-2019-0808 7.8 High
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...
Low complexity No user interaction
CVE-2021-26857 7.8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
Malware Low complexity
CVE-2020-1147 7.8 High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source...
Low complexity
CVE-2019-1214 7.8 High
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka...
Low complexity No user interaction
CVE-2016-3235 7.8 High
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which...
Low complexity
CVE-2019-0863 7.8 High
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of...
Low complexity No user interaction
CVE-2021-36955 7.8 High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Malware Low complexity No user interaction
CVE-2021-38648 7.8 High
Open Management Infrastructure Elevation of Privilege Vulnerability
Low complexity No user interaction
CVE-2020-6819 8.1 High
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in...
Remote No user interaction
CVE-2020-6820 8.1 High
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild...
Remote No user interaction
CVE-2019-17026 8.8 High
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks...
Remote Low complexity
CVE-2019-15949 8.8 High
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the...
Remote Low complexity No user interaction
Displaying vulnerabilities 2251 - 2275 of 2501 in total