Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2025-6554 | Google Chromium V8 Type Confusion Vulnerability | Severity: High CVSS 8.1 | Jul 2, 2025 | Not known | |
| CVE-2025-48927 | TeleMessage | TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability | Severity: Elevated CVSS 5.3 | Jul 1, 2025 | Not known |
| CVE-2025-48928 | TeleMessage | TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability | Severity: Elevated CVSS 4.0 | Jul 1, 2025 | Not known |
| CVE-2025-6543 | Citrix | Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability | Severity: Critical CVSS 9.2 | Jun 30, 2025 | Not known |
| CVE-2024-54085 | AMI | AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability | Severity: Critical CVSS 10.0 | Jun 25, 2025 | Not known |
| CVE-2024-0769 | D-Link | D-Link DIR-859 Router Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Jun 25, 2025 | Not known |
| CVE-2019-6693 | Fortinet | Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability | Severity: Elevated CVSS 6.5 | Jun 25, 2025 | Known |
| CVE-2023-0386 | Linux | Linux Kernel Improper Ownership Management Vulnerability | Severity: High CVSS 7.8 | Jun 17, 2025 | Not known |
| CVE-2023-33538 | TP-Link | TP-Link Multiple Routers Command Injection Vulnerability | Severity: High CVSS 8.8 | Jun 16, 2025 | Not known |
| CVE-2025-43200 | Apple | Apple Multiple Products Unspecified Vulnerability | Severity: Elevated CVSS 4.2 | Jun 16, 2025 | Not known |
| CVE-2025-24016 | Wazuh | Wazuh Server Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.9 | Jun 10, 2025 | Not known |
| CVE-2025-33053 | Microsoft | Microsoft Windows External Control of File Name or Path Vulnerability | Severity: High CVSS 8.8 | Jun 10, 2025 | Not known |
| CVE-2025-32433 | Erlang | Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability | Severity: Critical CVSS 10.0 | Jun 9, 2025 | Not known |
| CVE-2024-42009 | Roundcube | RoundCube Webmail Cross-Site Scripting Vulnerability | Severity: Critical CVSS 9.3 | Jun 9, 2025 | Not known |
| CVE-2025-5419 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | Severity: High CVSS 8.8 | Jun 5, 2025 | Not known | |
| CVE-2025-21479 | Qualcomm | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability | Severity: High CVSS 8.6 | Jun 3, 2025 | Not known |
| CVE-2025-21480 | Qualcomm | Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability | Severity: High CVSS 8.6 | Jun 3, 2025 | Not known |
| CVE-2025-27038 | Qualcomm | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | Severity: High CVSS 7.5 | Jun 3, 2025 | Not known |
| CVE-2021-32030 | ASUS | ASUS Routers Improper Authentication Vulnerability | Severity: Critical CVSS 9.8 | Jun 2, 2025 | Not known |
| CVE-2024-56145 | Craft CMS | Craft CMS Code Injection Vulnerability | Severity: Critical CVSS 9.3 | Jun 2, 2025 | Not known |
| CVE-2023-39780 | ASUS | ASUS RT-AX55 Routers OS Command Injection Vulnerability | Severity: High CVSS 8.8 | Jun 2, 2025 | Not known |
| CVE-2025-3935 | ConnectWise | ConnectWise ScreenConnect Improper Authentication Vulnerability | Severity: High CVSS 7.2 | Jun 2, 2025 | Not known |
| CVE-2025-35939 | Craft CMS | Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability | Severity: Elevated CVSS 6.9 | Jun 2, 2025 | Not known |
| CVE-2025-4632 | Samsung | Samsung MagicINFO 9 Server Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | May 22, 2025 | Not known |
| CVE-2025-27920 | Srimax | Srimax Output Messenger Directory Traversal Vulnerability | Severity: High CVSS 8.8 | May 19, 2025 | Not known |
| CVE-2025-4428 | Ivanti | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | Severity: High CVSS 8.8 | May 19, 2025 | Not known |
| CVE-2023-38950 | ZKTeco | ZKTeco BioTime Path Traversal Vulnerability | Severity: High CVSS 7.5 | May 19, 2025 | Not known |
| CVE-2025-4427 | Ivanti | Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability | Severity: High CVSS 7.5 | May 19, 2025 | Not known |
| CVE-2024-27443 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | May 19, 2025 | Not known |
| CVE-2024-11182 | MDaemon | MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 5.3 | May 19, 2025 | Not known |
| CVE-2025-42999 | SAP | SAP NetWeaver Deserialization Vulnerability | Severity: Critical CVSS 9.1 | May 15, 2025 | Known |
| CVE-2024-12987 | DrayTek | DrayTek Vigor Routers OS Command Injection Vulnerability | Severity: Elevated CVSS 6.9 | May 15, 2025 | Not known |
| CVE-2025-32756 | Fortinet | Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | May 14, 2025 | Not known |
| CVE-2025-30400 | Microsoft | Microsoft Windows DWM Core Library Use-After-Free Vulnerability | Severity: High CVSS 7.8 | May 13, 2025 | Not known |
| CVE-2025-32701 | Microsoft | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability | Severity: High CVSS 7.8 | May 13, 2025 | Not known |
| CVE-2025-32706 | Microsoft | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | May 13, 2025 | Not known |
| CVE-2025-32709 | Microsoft | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | Severity: High CVSS 7.8 | May 13, 2025 | Not known |
| CVE-2025-30397 | Microsoft | Microsoft Windows Scripting Engine Type Confusion Vulnerability | Severity: High CVSS 7.5 | May 13, 2025 | Not known |
| CVE-2025-47729 | TeleMessage | TeleMessage TM SGNL Hidden Functionality Vulnerability | Severity: Elevated CVSS 4.9 | May 12, 2025 | Not known |
| CVE-2024-11120 | GeoVision | GeoVision Devices OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | May 7, 2025 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
