Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2024-6047 | GeoVision | GeoVision Devices OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | May 7, 2025 | Not known |
| CVE-2025-27363 | FreeType | FreeType Out-of-Bounds Write Vulnerability | Severity: High CVSS 8.1 | May 6, 2025 | Not known |
| CVE-2025-3248 | Langflow | Langflow Missing Authentication Vulnerability | Severity: Critical CVSS 9.8 | May 5, 2025 | Known |
| CVE-2024-58136 | Yiiframework | Yiiframework Yii Improper Protection of Alternate Path Vulnerability | Severity: Critical CVSS 9.8 | May 2, 2025 | Not known |
| CVE-2025-34028 | Commvault | Commvault Command Center Path Traversal Vulnerability | Severity: Critical CVSS 9.3 | May 2, 2025 | Not known |
| CVE-2024-38475 | Apache | Apache HTTP Server Improper Escaping of Output Vulnerability | Severity: Critical CVSS 9.1 | May 1, 2025 | Not known |
| CVE-2023-44221 | SonicWall | SonicWall SMA100 Appliances OS Command Injection Vulnerability | Severity: High CVSS 7.2 | May 1, 2025 | Not known |
| CVE-2025-31324 | SAP | SAP NetWeaver Unrestricted File Upload Vulnerability | Severity: Critical CVSS 9.8 | Apr 29, 2025 | Known |
| CVE-2025-42599 | Qualitia | Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Apr 28, 2025 | Not known |
| CVE-2025-3928 | Commvault | Commvault Web Server Unspecified Vulnerability | Severity: High CVSS 8.7 | Apr 28, 2025 | Not known |
| CVE-2025-1976 | Broadcom | Broadcom Brocade Fabric OS Code Injection Vulnerability | Severity: High CVSS 8.6 | Apr 28, 2025 | Not known |
| CVE-2025-31200 | Apple | Apple Multiple Products Memory Corruption Vulnerability | Severity: Critical CVSS 9.8 | Apr 17, 2025 | Not known |
| CVE-2025-31201 | Apple | Apple Multiple Products Arbitrary Read and Write Vulnerability | Severity: Critical CVSS 9.8 | Apr 17, 2025 | Not known |
| CVE-2025-24054 | Microsoft | Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability | Severity: Elevated CVSS 5.4 | Apr 17, 2025 | Not known |
| CVE-2021-20035 | SonicWall | SonicWall SMA100 Appliances OS Command Injection Vulnerability | Severity: Elevated CVSS 6.5 | Apr 16, 2025 | Not known |
| CVE-2024-53197 | Linux | Linux Kernel Out-of-Bounds Access Vulnerability | Severity: High CVSS 7.8 | Apr 9, 2025 | Not known |
| CVE-2024-53150 | Linux | Linux Kernel Out-of-Bounds Read Vulnerability | Severity: High CVSS 7.1 | Apr 9, 2025 | Not known |
| CVE-2025-30406 | Gladinet | Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability | Severity: Critical CVSS 9.8 | Apr 8, 2025 | Not known |
| CVE-2025-29824 | Microsoft | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Apr 8, 2025 | Known |
| CVE-2025-31161 | CrushFTP | CrushFTP Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Apr 7, 2025 | Known |
| CVE-2025-22457 | Ivanti | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Apr 4, 2025 | Known |
| CVE-2025-24813 | Apache | Apache Tomcat Path Equivalence Vulnerability | Severity: Critical CVSS 9.8 | Apr 1, 2025 | Not known |
| CVE-2024-20439 | Cisco | Cisco Smart Licensing Utility Static Credential Vulnerability | Severity: Critical CVSS 9.8 | Mar 31, 2025 | Not known |
| CVE-2025-2783 | Google Chromium Mojo Sandbox Escape Vulnerability | Severity: High CVSS 8.3 | Mar 27, 2025 | Not known | |
| CVE-2019-9874 | Sitecore | Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability | Severity: Critical CVSS 9.8 | Mar 26, 2025 | Not known |
| CVE-2019-9875 | Sitecore | Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability | Severity: High CVSS 8.8 | Mar 26, 2025 | Not known |
| CVE-2025-30154 | reviewdog | reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability | Severity: High CVSS 8.6 | Mar 24, 2025 | Not known |
| CVE-2025-1316 | Edimax | Edimax IC-7100 IP Camera OS Command Injection Vulnerability | Severity: Critical CVSS 9.3 | Mar 19, 2025 | Not known |
| CVE-2024-48248 | NAKIVO | NAKIVO Backup and Replication Absolute Path Traversal Vulnerability | Severity: High CVSS 8.6 | Mar 19, 2025 | Not known |
| CVE-2017-12637 | SAP | SAP NetWeaver Directory Traversal Vulnerability | Severity: High CVSS 7.5 | Mar 19, 2025 | Not known |
| CVE-2025-30066 | tj-actions | tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability | Severity: High CVSS 8.6 | Mar 18, 2025 | Not known |
| CVE-2025-24472 | Fortinet | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Severity: High CVSS 8.1 | Mar 18, 2025 | Known |
| CVE-2025-24201 | Apple | Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability | Severity: Critical CVSS 10.0 | Mar 13, 2025 | Not known |
| CVE-2025-21590 | Juniper | Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability | Severity: Elevated CVSS 6.7 | Mar 13, 2025 | Not known |
| CVE-2025-24985 | Microsoft | Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability | Severity: High CVSS 7.8 | Mar 11, 2025 | Not known |
| CVE-2025-24993 | Microsoft | Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Mar 11, 2025 | Not known |
| CVE-2025-24983 | Microsoft | Microsoft Windows Win32k Use-After-Free Vulnerability | Severity: High CVSS 7.0 | Mar 11, 2025 | Not known |
| CVE-2025-26633 | Microsoft | Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability | Severity: High CVSS 7.0 | Mar 11, 2025 | Known |
| CVE-2025-24991 | Microsoft | Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability | Severity: Elevated CVSS 5.5 | Mar 11, 2025 | Not known |
| CVE-2025-24984 | Microsoft | Microsoft Windows NTFS Information Disclosure Vulnerability | Severity: Elevated CVSS 4.6 | Mar 11, 2025 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
