Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2017-5070 Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. HIGH 8.8 31.21% cvelistv5 2026-06-17
cve-2017-5030 Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page. HIGH 8.8 41.69% cvelistv5 2026-06-17
cve-2016-5198 SUSE CVE CVE-2016-5198 HIGH 8.8 34.16% cvelistv5 2026-09-02
cve-2016-1646 Google Chromium V8 Out-of-Bounds Read Vulnerability HIGH N/A 48.11% cvelistv5 2022-06-08
cve-2013-1331 Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability." HIGH 7.8 81.75% cvelistv5 2026-06-16
cve-2012-5054 Adobe Flash Player Integer Overflow Vulnerability HIGH N/A 21.19% cvelistv5 2022-06-08
cve-2012-4969 Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012. HIGH 8.1 81.72% cvelistv5 2026-06-16
cve-2012-1889 Microsoft XML Core Services Memory Corruption Vulnerability HIGH N/A 83.52% cvelistv5 2022-06-08
cve-2012-0767 Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012. MEDIUM 6.1 6.66% cvelistv5 2026-06-16
cve-2012-0754 Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. HIGH 8.1 92.03% cvelistv5 2026-06-16
cve-2012-0151 The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability." HIGH 7.8 88.78% cvelistv5 2026-06-16
cve-2011-2462 Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011. CRITICAL 9.8 86.56% cvelistv5 2026-06-16
cve-2011-0609 Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011. HIGH 7.8 66.82% cvelistv5 2026-06-16
cve-2010-2883 Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information. HIGH 7.3 82.36% cvelistv5 2026-06-16
cve-2010-2572 Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability." HIGH 7.8 62.48% cvelistv5 2026-06-16
cve-2010-1297 Adobe Flash Player Memory Corruption Vulnerability HIGH N/A 82.24% cvelistv5 2022-06-08
cve-2009-4324 Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009. HIGH 7.8 81.93% cvelistv5 2026-06-16
cve-2009-3953 The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994. HIGH 8.8 83.86% cvelistv5 2026-06-16
cve-2009-1862 Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009. HIGH 7.8 24.92% cvelistv5 2026-06-16
cve-2009-0563 Microsoft Office Buffer Overflow Vulnerability HIGH N/A 62.83% cvelistv5 2022-06-08
cve-2009-0557 Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Object Record Corruption Vulnerability." HIGH 7.8 58.55% cvelistv5 2026-06-16
cve-2008-0655 Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. HIGH 8.8 38.91% cvelistv5 2026-06-16
cve-2007-5659 Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655. HIGH 7.8 94.02% cvelistv5 2026-06-16
cve-2006-2492 Microsoft Word Malformed Object Pointer Vulnerability HIGH N/A 48.11% cvelistv5 2022-06-08
cve-2022-26134 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability CRITICAL 9.8 100.00% cvelistv5 2022-06-02
cve-2019-3010 Oracle Solaris Privilege Escalation Vulnerability HIGH 8.8 13.40% cvelistv5 2022-05-25
cve-2016-7256 Microsoft Windows Open Type Font Remote Code Execution Vulnerability HIGH N/A 64.59% cvelistv5 2022-05-25
cve-2016-3393 Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability HIGH N/A 68.47% cvelistv5 2022-05-25
cve-2016-1010 Adobe Flash Player and AIR Integer Overflow Vulnerability HIGH N/A 19.33% cvelistv5 2022-05-25
cve-2016-0984 Adobe Flash Player and AIR Use-After-Free Vulnerability HIGH N/A 54.54% cvelistv5 2022-05-25