CISA · government feed

Known Exploited Vulnerabilities

Vulnerabilities under active exploitation, mandated by CISA for federal patching.

369 total matches · showing 200

CVEVendor / ProductStatus
CVE-2026-33825
Microsoft
Defender
Active
CVE-2026-32201
Microsoft
SharePoint Server
Active
CVE-2009-0238
Microsoft
Office
Active
CVE-2023-36424
Microsoft
Windows
Active
CVE-2023-21529
Microsoft
Exchange Server
Ransomware
CVE-2025-60710
Microsoft
Windows
Active
CVE-2012-1854
Microsoft
Visual Basic for Applications (VBA)
Active
CVE-2026-20963
Microsoft
SharePoint
Active
CVE-2008-0015
Microsoft
Windows
Active
CVE-2024-43468
Microsoft
Configuration Manager
Active
CVE-2026-21514
Microsoft
Office
Active
CVE-2026-21519
Microsoft
Windows
Active
CVE-2026-21533
Microsoft
Windows
Active
CVE-2026-21510
Microsoft
Windows
Active
CVE-2026-21525
Microsoft
Windows
Active
CVE-2026-21513
Microsoft
Windows
Active
CVE-2026-21509
Microsoft
Office
Active
CVE-2026-20805
Microsoft
Windows
Active
CVE-2009-0556
Microsoft
Office
Active
CVE-2025-62221
Microsoft
Windows
Active
CVE-2025-62215
Microsoft
Windows
Active
CVE-2025-59287
Microsoft
Windows
Active
CVE-2025-33073
Microsoft
Windows
Active
CVE-2025-59230
Microsoft
Windows
Active
CVE-2025-24990
Microsoft
Windows
Active
CVE-2011-3402
Microsoft
Windows
Active
CVE-2013-3918
Microsoft
Windows
Active
CVE-2021-43226
Microsoft
Windows
Active
CVE-2010-3962
Microsoft
Internet Explorer
Active
CVE-2013-3893
Microsoft
Internet Explorer
Active
CVE-2007-0671
Microsoft
Office
Active
CVE-2025-49706
Microsoft
SharePoint
Ransomware
CVE-2025-49704
Microsoft
SharePoint
Ransomware
CVE-2025-53770
Microsoft
SharePoint
Ransomware
CVE-2025-33053
Microsoft
Windows
Active
CVE-2025-30400
Microsoft
Windows
Active
CVE-2025-32701
Microsoft
Windows
Active
CVE-2025-32706
Microsoft
Windows
Active
CVE-2025-30397
Microsoft
Windows
Active
CVE-2025-32709
Microsoft
Windows
Active
CVE-2025-24054
Microsoft
Windows
Active
CVE-2025-29824
Microsoft
Windows
Ransomware
CVE-2025-26633
Microsoft
Windows
Ransomware
CVE-2025-24983
Microsoft
Windows
Active
CVE-2025-24984
Microsoft
Windows
Active
CVE-2025-24985
Microsoft
Windows
Active
CVE-2025-24991
Microsoft
Windows
Active
CVE-2025-24993
Microsoft
Windows
Active
CVE-2018-8639
Microsoft
Windows
Ransomware
CVE-2024-49035
Microsoft
Partner Center
Active
CVE-2025-24989
Microsoft
Power Pages
Active
CVE-2025-21391
Microsoft
Windows
Active
CVE-2025-21418
Microsoft
Windows
Active
CVE-2024-21413
Microsoft
Office Outlook
Active
CVE-2024-29059
Microsoft
.NET Framework
Active
CVE-2025-21333
Microsoft
Windows
Active
CVE-2025-21334
Microsoft
Windows
Active
CVE-2025-21335
Microsoft
Windows
Active
CVE-2024-35250
Microsoft
Windows
Active
CVE-2024-49138
Microsoft
Windows
Active
CVE-2024-49039
Microsoft
Windows
Ransomware
CVE-2024-43451
Microsoft
Windows
Active
CVE-2024-38094
Microsoft
SharePoint
Ransomware
CVE-2024-30088
Microsoft
Windows
Ransomware
CVE-2024-43572
Microsoft
Windows
Active
CVE-2024-43573
Microsoft
Windows
Active
CVE-2020-0618
Microsoft
SQL Server
Active
CVE-2024-43461
Microsoft
Windows
Active
CVE-2024-38226
Microsoft
Publisher
Active
CVE-2024-38014
Microsoft
Windows
Active
CVE-2024-38217
Microsoft
Windows
Active
CVE-2021-31196
Microsoft
Exchange Server
Active
CVE-2024-38189
Microsoft
Project
Active
CVE-2024-38178
Microsoft
Windows
Active
CVE-2024-38213
Microsoft
Windows
Active
CVE-2024-38193
Microsoft
Windows
Active
CVE-2024-38106
Microsoft
Windows
Active
CVE-2024-38107
Microsoft
Windows
Active
CVE-2018-0824
Microsoft
Windows
Active
CVE-2012-4792
Microsoft
Internet Explorer
Active
CVE-2024-38112
Microsoft
Windows
Active
CVE-2024-38080
Microsoft
Windows
Active
CVE-2024-26169
Microsoft
Windows
Ransomware
CVE-2024-30051
Microsoft
DWM Core Library
Ransomware
CVE-2024-30040
Microsoft
Windows
Active
CVE-2024-29988
Microsoft
SmartScreen Prompt
Active
CVE-2022-38028
Microsoft
Windows
Active
CVE-2023-24955
Microsoft
SharePoint Server
Ransomware
CVE-2024-21338
Microsoft
Windows
Ransomware
CVE-2023-29360
Microsoft
Streaming Service
Active
CVE-2024-21410
Microsoft
Exchange Server
Active
CVE-2024-21351
Microsoft
Windows
Active
CVE-2024-21412
Microsoft
Windows
Ransomware
CVE-2023-29357
Microsoft
SharePoint Server
Ransomware
CVE-2023-36584
Microsoft
Windows
Active
CVE-2023-36036
Microsoft
Windows
Active
CVE-2023-36025
Microsoft
Windows
Active
CVE-2023-36033
Microsoft
Windows
Active
CVE-2023-36563
Microsoft
WordPad
Active
CVE-2023-41763
Microsoft
Skype for Business
Active
CVE-2023-28229
Microsoft
Windows CNG Key Isolation Service
Active
CVE-2023-36802
Microsoft
Streaming Service Proxy
Active
CVE-2023-36761
Microsoft
Word
Active
CVE-2023-38180
Microsoft
.NET Core and Visual Studio
Active
CVE-2023-36884
Microsoft
Windows
Ransomware
CVE-2023-36874
Microsoft
Windows
Active
CVE-2023-35311
Microsoft
Outlook
Active
CVE-2023-32049
Microsoft
Windows
Active
CVE-2023-32046
Microsoft
Windows
Active
CVE-2016-0165
Microsoft
Win32k
Active
CVE-2023-29336
Microsoft
Win32k
Active
CVE-2023-28252
Microsoft
Windows
Ransomware
CVE-2019-1388
Microsoft
Windows
Ransomware
CVE-2013-3163
Microsoft
Internet Explorer
Active
CVE-2023-24880
Microsoft
Windows
Ransomware
CVE-2023-23397
Microsoft
Office
Active
CVE-2023-21823
Microsoft
Windows
Active
CVE-2023-23376
Microsoft
Windows
Ransomware
CVE-2023-21715
Microsoft
Office
Active
CVE-2023-21674
Microsoft
Windows
Active
CVE-2022-41080
Microsoft
Exchange Server
Ransomware
CVE-2022-44698
Microsoft
Defender
Ransomware
CVE-2022-41049
Microsoft
Windows
Active
CVE-2022-41128
Microsoft
Windows
Active
CVE-2022-41125
Microsoft
Windows
Active
CVE-2022-41073
Microsoft
Windows
Ransomware
CVE-2022-41091
Microsoft
Windows
Ransomware
CVE-2022-41033
Microsoft
Windows COM+ Event System Service
Active
CVE-2022-41040
Microsoft
Exchange Server
Ransomware
CVE-2022-41082
Microsoft
Exchange Server
Ransomware
CVE-2010-2568
Microsoft
Windows
Active
CVE-2022-37969
Microsoft
Windows
Active
CVE-2022-21971
Microsoft
Windows
Active
CVE-2022-26923
Microsoft
Active Directory
Active
CVE-2022-34713
Microsoft
Windows
Active
CVE-2022-22047
Microsoft
Windows
Active
CVE-2022-26925
Microsoft
Windows
Active
CVE-2022-30190
Microsoft
Windows
Ransomware
CVE-2006-2492
Microsoft
Word
Active
CVE-2009-0557
Microsoft
Office
Active
CVE-2009-0563
Microsoft
Office
Active
CVE-2010-2572
Microsoft
PowerPoint
Active
CVE-2012-0151
Microsoft
Windows
Active
CVE-2012-1889
Microsoft
XML Core Services
Active
CVE-2012-4969
Microsoft
Internet Explorer
Active
CVE-2013-1331
Microsoft
Office
Active
CVE-2013-0074
Microsoft
Silverlight
Ransomware
CVE-2013-3896
Microsoft
Silverlight
Active
CVE-2013-7331
Microsoft
Internet Explorer
Active
CVE-2014-4077
Microsoft
Input Method Editor (IME) Japanese
Active
CVE-2014-2817
Microsoft
Internet Explorer
Active
CVE-2014-4123
Microsoft
Internet Explorer
Active
CVE-2014-4148
Microsoft
Windows
Active
CVE-2015-1671
Microsoft
Windows
Active
CVE-2015-6175
Microsoft
Windows
Active
CVE-2015-1769
Microsoft
Windows
Active
CVE-2015-2425
Microsoft
Internet Explorer
Active
CVE-2015-2360
Microsoft
Win32k
Active
CVE-2015-0071
Microsoft
Internet Explorer
Active
CVE-2015-0016
Microsoft
Windows
Active
CVE-2016-0034
Microsoft
Silverlight
Ransomware
CVE-2016-7256
Microsoft
Windows
Active
CVE-2016-3393
Microsoft
Windows
Active
CVE-2016-3298
Microsoft
Internet Explorer
Active
CVE-2016-3351
Microsoft
Internet Explorer and Edge
Ransomware
CVE-2016-0162
Microsoft
Internet Explorer
Active
CVE-2017-8543
Microsoft
Windows
Active
CVE-2017-0210
Microsoft
Internet Explorer
Active
CVE-2017-0149
Microsoft
Internet Explorer
Active
CVE-2017-0005
Microsoft
Windows
Active
CVE-2017-0022
Microsoft
XML Core Services
Active
CVE-2017-0147
Microsoft
SMBv1 server
Ransomware
CVE-2018-8611
Microsoft
Windows
Active
CVE-2018-8589
Microsoft
Win32k
Active
CVE-2019-1130
Microsoft
Windows
Ransomware
CVE-2019-1385
Microsoft
Windows
Ransomware
CVE-2019-0880
Microsoft
Windows
Active
CVE-2019-0703
Microsoft
Windows
Active
CVE-2019-0676
Microsoft
Internet Explorer
Active
CVE-2020-0638
Microsoft
Update Notification Manager
Ransomware
CVE-2020-1027
Microsoft
Windows
Active
CVE-2014-0322
Microsoft
Internet Explorer
Active
CVE-2014-4113
Microsoft
Win32k
Active
CVE-2021-40450
Microsoft
Win32k
Active
CVE-2021-41357
Microsoft
Win32k
Active
CVE-2022-21919
Microsoft
Windows
Active
CVE-2022-26904
Microsoft
Windows
Active
CVE-2022-22718
Microsoft
Windows
Active
CVE-2015-2502
Microsoft
Internet Explorer
Active
CVE-2022-24521
Microsoft
Windows
Ransomware
CVE-2021-42278
Microsoft
Active Directory
Ransomware
CVE-2021-42287
Microsoft
Active Directory
Ransomware
CVE-2017-0148
Microsoft
SMBv1 server
Ransomware
CVE-2021-31166
Microsoft
HTTP Protocol Stack
Active
CVE-2021-34484
Microsoft
Windows
Active
CVE-2010-4398
Microsoft
Windows
Active
CVE-2011-2005
Microsoft
Ancillary Function Driver (afd.sys)
Active
CVE-2012-2539
Microsoft
Word
Active
CVE-2013-2551
Microsoft
Internet Explorer
Ransomware
CVE-2013-3660
Microsoft
Win32k
Active
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000