KEV 2010
23 CISA Known Exploited Vulnerabilities from 2010
Critical 6
October 2025
May 2022
April 2022
March 2022
Adobe ColdFusion — Directory Traversal in Administrator Console Enables Arbitrary File Read; Ransomware Pre-Deployment Vector
CVSS 9.8Exim MTA — string_vformat() Heap Overflow via Crafted SMTP Session Enables Unauthenticated Remote Code Execution
CVSS 9.8November 2021
High 16
May 2026
Internet Explorer — Use-After-Free via Deleted HTML Object Enables RCE; Operation Aurora Chinese APT Campaign Targeting Google, Adobe, and Others; Emergency MS10-002 January 2010
CVSS 8.8Internet Explorer 6/7 — Use-After-Free in iepeers.dll Peer Objects Enables Drive-By RCE; Zero-Day Before Emergency MS10-018 March 2010
CVSS 8.8October 2025
May 2023
September 2022
June 2022
Adobe Flash Player — Memory Corruption Zero-Day Enables Code Execution via Malicious SWF in Browser or PDF
CVSS 7.8Microsoft PowerPoint — Crafted Presentation File Triggers Buffer Overflow and Remote Code Execution via MS10-088
CVSS 7.8Adobe Acrobat and Reader — CoolType.dll SING Table Stack Overflow Enables Code Execution via Malicious PDF; Exploited as Zero-Day
CVSS 7.3May 2022
March 2022
Microsoft Windows win32k.sys — RtlQueryRegistryValues Stack Overflow Enables Local Privilege Escalation and UAC Bypass
CVSS 7.8Exim MTA — Alternate Configuration File Directive Enables Privilege Escalation from Exim User to Root
CVSS 7.8Adobe Reader and Acrobat — Unspecified Vulnerability Enables Code Execution; Exploited in Ransomware Delivery Campaigns
CVSS 7.8Microsoft Windows NTVDM — Improper BIOS Call Validation in 16-bit App Support Enables Local Privilege Escalation
CVSS 7.8Microsoft Office RTF — pFragments Property Stack Overflow Enables Remote Code Execution; Exploited as Zero-Day in Targeted Attacks
CVSS 7.8Cisco IOS XR — Malformed BGP UPDATE Message Causes Routing Process Crash; Second BGP DoS Vulnerability Affecting Carrier Infrastructure
CVSS 7.5