Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2009-4324 Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009. HIGH 7.8 81.93% cvelistv5 2026-06-16
cve-2009-3953 The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994. HIGH 8.8 83.86% cvelistv5 2026-06-16
cve-2009-1862 Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009. HIGH 7.8 24.92% cvelistv5 2026-06-16
cve-2009-0563 Microsoft Office Buffer Overflow Vulnerability HIGH N/A 62.83% cvelistv5 2022-06-08
cve-2009-0557 Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Object Record Corruption Vulnerability." HIGH 7.8 58.55% cvelistv5 2026-06-16
cve-2008-0655 Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. HIGH 8.8 38.91% cvelistv5 2026-06-16
cve-2007-5659 Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655. HIGH 7.8 94.02% cvelistv5 2026-06-16
cve-2006-2492 Microsoft Word Malformed Object Pointer Vulnerability HIGH N/A 48.11% cvelistv5 2022-06-08
cve-2022-26134 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability CRITICAL 9.8 100.00% cvelistv5 2022-06-02
cve-2019-3010 Oracle Solaris Privilege Escalation Vulnerability HIGH 8.8 13.40% cvelistv5 2022-05-25
cve-2016-7256 Microsoft Windows Open Type Font Remote Code Execution Vulnerability HIGH N/A 64.59% cvelistv5 2022-05-25
cve-2016-3393 Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability HIGH N/A 68.47% cvelistv5 2022-05-25
cve-2016-1010 Adobe Flash Player and AIR Integer Overflow Vulnerability HIGH N/A 19.33% cvelistv5 2022-05-25
cve-2016-0984 Adobe Flash Player and AIR Use-After-Free Vulnerability HIGH N/A 54.54% cvelistv5 2022-05-25
cve-2016-0034 Microsoft Silverlight Runtime Remote Code Execution Vulnerability CRITICAL N/A 69.40% cvelistv5 2022-05-25
cve-2015-8651 SUSE CVE CVE-2015-8651 HIGH 8.8 67.70% cvelistv5 2025-10-07
cve-2015-6175 Microsoft Windows Kernel Privilege Escalation Vulnerability HIGH N/A 5.13% cvelistv5 2022-05-25
cve-2015-4495 The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015. HIGH 8.8 71.34% cvelistv5 2026-06-17
cve-2015-2425 Microsoft Internet Explorer Memory Corruption Vulnerability HIGH N/A 44.73% cvelistv5 2022-05-25
cve-2015-2360 Microsoft Win32k Privilege Escalation Vulnerability HIGH N/A 14.84% cvelistv5 2022-05-25
cve-2015-1769 Microsoft Windows Mount Manager Privilege Escalation Vulnerability HIGH N/A 4.08% cvelistv5 2022-05-25
cve-2015-1671 The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before 5.1.40416.00, allows remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability." HIGH 7.8 54.63% cvelistv5 2026-06-17
cve-2015-0310 SUSE CVE CVE-2015-0310 UNKNOWN N/A 15.10% cvelistv5 2025-11-21
cve-2015-0071 Microsoft Internet Explorer ASLR Bypass Vulnerability MEDIUM 6.5 33.58% cvelistv5 2022-05-25
cve-2015-0016 Microsoft Windows TS WebProxy Directory Traversal Vulnerability HIGH N/A 75.78% cvelistv5 2022-05-25
cve-2014-8439 Adobe Flash Player Dereferenced Pointer Vulnerability HIGH N/A 20.37% cvelistv5 2022-05-25
cve-2014-4148 Microsoft Windows Remote Code Execution Vulnerability HIGH N/A 59.85% cvelistv5 2022-05-25
cve-2014-4123 Microsoft Internet Explorer Privilege Escalation Vulnerability HIGH N/A 47.13% cvelistv5 2022-05-25
cve-2014-4077 Microsoft IME Japanese Privilege Escalation Vulnerability HIGH N/A 54.58% cvelistv5 2022-05-25
cve-2014-3153 Linux Kernel Privilege Escalation Vulnerability HIGH N/A 37.23% cvelistv5 2022-05-25