Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2024-57968 | Advantive | Advantive VeraCore Unrestricted File Upload Vulnerability | Severity: High CVSS 8.8 | Mar 10, 2025 | Not known |
| CVE-2024-13159 | Ivanti | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Severity: High CVSS 7.5 | Mar 10, 2025 | Not known |
| CVE-2024-13160 | Ivanti | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Severity: High CVSS 7.5 | Mar 10, 2025 | Not known |
| CVE-2024-13161 | Ivanti | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Severity: High CVSS 7.5 | Mar 10, 2025 | Not known |
| CVE-2025-25181 | Advantive | Advantive VeraCore SQL Injection Vulnerability | Severity: High CVSS 7.5 | Mar 10, 2025 | Not known |
| CVE-2025-22224 | VMware | VMware ESXi and Workstation TOCTOU Race Condition Vulnerability | Severity: High CVSS 8.2 | Mar 4, 2025 | Not known |
| CVE-2025-22225 | VMware | VMware ESXi Arbitrary Write Vulnerability | Severity: High CVSS 8.2 | Mar 4, 2025 | Known |
| CVE-2025-22226 | VMware | VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability | Severity: Elevated CVSS 6.0 | Mar 4, 2025 | Not known |
| CVE-2024-50302 | Linux | Linux Kernel Use of Uninitialized Resource Vulnerability | Severity: Elevated CVSS 5.5 | Mar 4, 2025 | Not known |
| CVE-2022-43939 | Hitachi Vantara | Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability | Severity: Critical CVSS 9.8 | Mar 3, 2025 | Not known |
| CVE-2024-4885 | Progress | Progress WhatsUp Gold Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Mar 3, 2025 | Not known |
| CVE-2018-8639 | Microsoft | Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2025 | Known |
| CVE-2022-43769 | Hitachi Vantara | Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability | Severity: High CVSS 7.2 | Mar 3, 2025 | Not known |
| CVE-2023-20118 | Cisco | Cisco Small Business RV Series Routers Command Injection Vulnerability | Severity: High CVSS 7.2 | Mar 3, 2025 | Not known |
| CVE-2024-49035 | Microsoft | Microsoft Partner Center Improper Access Control Vulnerability | Severity: Critical CVSS 9.8 | Feb 25, 2025 | Not known |
| CVE-2023-34192 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | Severity: Critical CVSS 9.0 | Feb 25, 2025 | Not known |
| CVE-2017-3066 | Adobe | Adobe ColdFusion Deserialization Vulnerability | Severity: Critical CVSS 9.8 | Feb 24, 2025 | Not known |
| CVE-2024-20953 | Oracle | Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability | Severity: High CVSS 8.8 | Feb 24, 2025 | Not known |
| CVE-2025-24989 | Microsoft | Microsoft Power Pages Improper Access Control Vulnerability | Severity: Critical CVSS 9.8 | Feb 21, 2025 | Not known |
| CVE-2025-23209 | Craft CMS | Craft CMS Code Injection Vulnerability | Severity: High CVSS 8.1 | Feb 20, 2025 | Not known |
| CVE-2025-0111 | Palo Alto Networks | Palo Alto Networks PAN-OS File Read Vulnerability | Severity: High CVSS 7.1 | Feb 20, 2025 | Not known |
| CVE-2024-53704 | SonicWall | SonicWall SonicOS SSLVPN Improper Authentication Vulnerability | Severity: Critical CVSS 9.8 | Feb 18, 2025 | Known |
| CVE-2025-0108 | Palo Alto Networks | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | Severity: High CVSS 8.8 | Feb 18, 2025 | Not known |
| CVE-2024-57727 | SimpleHelp | SimpleHelp Path Traversal Vulnerability | Severity: High CVSS 7.5 | Feb 13, 2025 | Known |
| CVE-2024-41710 | Mitel | Mitel SIP Phones Argument Injection Vulnerability | Severity: High CVSS 7.2 | Feb 12, 2025 | Not known |
| CVE-2025-24200 | Apple | Apple iOS and iPadOS Incorrect Authorization Vulnerability | Severity: Elevated CVSS 6.1 | Feb 12, 2025 | Not known |
| CVE-2024-40890 | Zyxel | Zyxel DSL CPE OS Command Injection Vulnerability | Severity: High CVSS 8.8 | Feb 11, 2025 | Not known |
| CVE-2024-40891 | Zyxel | Zyxel DSL CPE OS Command Injection Vulnerability | Severity: High CVSS 8.8 | Feb 11, 2025 | Not known |
| CVE-2025-21418 | Microsoft | Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Feb 11, 2025 | Not known |
| CVE-2025-21391 | Microsoft | Microsoft Windows Storage Link Following Vulnerability | Severity: High CVSS 7.1 | Feb 11, 2025 | Not known |
| CVE-2025-0994 | Trimble | Trimble Cityworks Deserialization Vulnerability | Severity: High CVSS 8.6 | Feb 7, 2025 | Not known |
| CVE-2020-15069 | Sophos | Sophos XG Firewall Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Feb 6, 2025 | Not known |
| CVE-2020-29574 | Sophos | CyberoamOS (CROS) SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Feb 6, 2025 | Known |
| CVE-2024-21413 | Microsoft | Microsoft Outlook Improper Input Validation Vulnerability | Severity: Critical CVSS 9.8 | Feb 6, 2025 | Not known |
| CVE-2022-23748 | Audinate | Dante Discovery Process Control Vulnerability | Severity: High CVSS 7.8 | Feb 6, 2025 | Not known |
| CVE-2025-0411 | 7-Zip | 7-Zip Mark of the Web Bypass Vulnerability | Severity: High CVSS 7.0 | Feb 6, 2025 | Not known |
| CVE-2024-53104 | Linux | Linux Kernel Out-of-Bounds Write Vulnerability | Severity: High CVSS 7.8 | Feb 5, 2025 | Not known |
| CVE-2018-19410 | Paessler | Paessler PRTG Network Monitor Local File Inclusion Vulnerability | Severity: Critical CVSS 9.8 | Feb 4, 2025 | Not known |
| CVE-2024-29059 | Microsoft | Microsoft .NET Framework Information Disclosure Vulnerability | Severity: High CVSS 7.5 | Feb 4, 2025 | Not known |
| CVE-2024-45195 | Apache | Apache OFBiz Forced Browsing Vulnerability | Severity: High CVSS 7.5 | Feb 4, 2025 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
