Full CISA KEV catalog
Every CVE the U.S. cybersecurity agency has flagged as actively exploited. Search by vendor or product. Filter by category, time window, or ransomware association. Paginated 50 per page.
| CVE | Vendor / product | Vulnerability | Categories | Added to KEV |
|---|---|---|---|---|
| CVE-2025-48595 |
Android
Framework
|
Android Framework Integer Overflow Vulnerability
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
|
Mobile | Jun 2, 2026 |
| CVE-2025-43510 |
Apple
Multiple Products
|
Apple Multiple Products Improper Locking Vulnerability
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes.
|
Mobile | Mar 20, 2026 |
| CVE-2025-43520 |
Apple
Multiple Products
|
Apple Multiple Products Classic Buffer Overflow Vulnerability
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer overflow vulnerability which could allow a malicious application to cause unexpected system termination or write kernel memory.
|
Mobile | Mar 20, 2026 |
| CVE-2025-31277 |
Apple
Multiple Products
|
Apple Multiple Products Buffer Overflow Vulnerability
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer overflow vulnerability that could allow the processing of maliciously crafted web content which may lead to memory corruption.
|
Browsers Mobile | Mar 20, 2026 |
| CVE-2026-3909 |
Google
Skia
|
Google Skia Out-of-Bounds Write Vulnerability
Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
|
Browsers Mobile | Mar 13, 2026 |
| CVE-2023-43000 |
Apple
Multiple Products
|
Apple Multiple products Use-After-Free Vulnerability
Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption.
|
Browsers Mobile | Mar 5, 2026 |
| CVE-2021-30952 |
Apple
Multiple Products
|
Apple Multiple Products Integer Overflow or Wraparound Vulnerability
Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution.
|
Browsers Mobile | Mar 5, 2026 |
| CVE-2023-41974 |
Apple
iOS and iPadOS
|
Apple iOS and iPadOS Use-After-Free Vulnerability
Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.
|
Mobile | Mar 5, 2026 |
| CVE-2026-21385 |
Qualcomm
Multiple Chipsets
|
Qualcomm Multiple Chipsets Memory Corruption Vulnerability
Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation.
|
Mobile | Mar 3, 2026 |
| CVE-2026-20700 |
Apple
Multiple Products
|
Apple Multiple Buffer Overflow Vulnerability
Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code.
|
Mobile | Feb 12, 2026 |
| CVE-2025-43529 |
Apple
Multiple Products
|
Apple Multiple Products Use-After-Free WebKit Vulnerability
Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
|
Browsers Mobile | Dec 15, 2025 |
| CVE-2025-48633 |
Android
Framework
|
Android Framework Information Disclosure Vulnerability
Android Framework contains an unspecified vulnerability that allows for information disclosure.
|
Mobile | Dec 2, 2025 |
| CVE-2025-48572 |
Android
Framework
|
Android Framework Privilege Escalation Vulnerability
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
|
Mobile | Dec 2, 2025 |
| CVE-2025-21042 |
Samsung
Mobile Devices
|
Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.
|
Mobile | Nov 10, 2025 |
| CVE-2025-21043 |
Samsung
Mobile Devices
|
Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code.
|
Mobile | Oct 2, 2025 |
| CVE-2025-48543 |
Android
Runtime
|
Android Runtime Use-After-Free Vulnerability
Android Runtime contains a use-after-free vulnerability potentially allowing a chrome sandbox escape leading to local privilege escalation.
|
Browsers Mobile | Sep 4, 2025 |
| CVE-2025-43300 |
Apple
iOS, iPadOS, and macOS
|
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.
|
Mobile | Aug 21, 2025 |
| CVE-2025-43200 |
Apple
Multiple Products
|
Apple Multiple Products Unspecified Vulnerability
Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.
|
Mobile | Jun 16, 2025 |
| CVE-2025-21479 |
Qualcomm
Multiple Chipsets
|
Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
|
Mobile | Jun 3, 2025 |
| CVE-2025-21480 |
Qualcomm
Multiple Chipsets
|
Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
|
Mobile | Jun 3, 2025 |
| CVE-2025-27038 |
Qualcomm
Multiple Chipsets
|
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
|
Browsers Mobile | Jun 3, 2025 |
| CVE-2025-31201 |
Apple
Multiple Products
|
Apple Multiple Products Arbitrary Read and Write Vulnerability
Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.
|
Mobile | Apr 17, 2025 |
| CVE-2025-31200 |
Apple
Multiple Products
|
Apple Multiple Products Memory Corruption Vulnerability
Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.
|
Mobile | Apr 17, 2025 |
| CVE-2025-24201 |
Apple
Multiple Products
|
Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
|
Browsers Mobile | Mar 13, 2025 |
| CVE-2025-24200 |
Apple
iOS and iPadOS
|
Apple iOS and iPadOS Incorrect Authorization Vulnerability
Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.
|
Mobile | Feb 12, 2025 |
| CVE-2025-24085 |
Apple
Multiple Products
|
Apple Multiple Products Use-After-Free Vulnerability
Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.
|
Mobile | Jan 29, 2025 |
| CVE-2024-44309 |
Apple
Multiple Products
|
Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability
Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to a cross-site scripting (XSS) attack.
|
Mobile | Nov 21, 2024 |
| CVE-2024-44308 |
Apple
Multiple Products
|
Apple Multiple Products Code Execution Vulnerability
Apple iOS, macOS, and other Apple products contain an unspecified vulnerability when processing maliciously crafted web content that may lead to arbitrary code execution.
|
Mobile | Nov 21, 2024 |
| CVE-2024-43093 |
Android
Framework
|
Android Framework Privilege Escalation Vulnerability
Android Framework contains an unspecified vulnerability that allows for privilege escalation.
|
Mobile | Nov 7, 2024 |
| CVE-2024-43047 |
Qualcomm
Multiple Chipsets
|
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.
|
Mobile | Oct 8, 2024 |
| CVE-2024-36971 |
Android
Kernel
|
Android Kernel Remote Code Execution Vulnerability
Android contains an unspecified vulnerability in the kernel that allows for remote code execution. This vulnerability resides in Linux Kernel and could impact other products, including but not limited to Android OS.
|
Server OS / DB / Web Mobile Yacht-focused | Aug 7, 2024 |
| CVE-2024-32896 |
Android
Pixel
|
Android Pixel Privilege Escalation Vulnerability
Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.
|
Mobile | Jun 13, 2024 |
Source: CISA Known Exploited Vulnerabilities catalog. Updated hourly. Want crew who know what to do when one of these lands aboard? Start the free crew course →