Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2018-9276 | Paessler | Paessler PRTG Network Monitor OS Command Injection Vulnerability | Severity: High CVSS 7.2 | Feb 4, 2025 | Not known |
| CVE-2025-24085 | Apple | Apple Multiple Products Use-After-Free Vulnerability | Severity: Critical CVSS 10.0 | Jan 29, 2025 | Not known |
| CVE-2025-23006 | SonicWall | SonicWall SMA1000 Appliances Deserialization Vulnerability | Severity: Critical CVSS 9.8 | Jan 24, 2025 | Known |
| CVE-2020-11023 | JQuery | JQuery Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Jan 23, 2025 | Not known |
| CVE-2024-50603 | Aviatrix | Aviatrix Controllers OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Jan 16, 2025 | Not known |
| CVE-2024-55591 | Fortinet | Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Jan 14, 2025 | Known |
| CVE-2025-21333 | Microsoft | Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Jan 14, 2025 | Not known |
| CVE-2025-21334 | Microsoft | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Jan 14, 2025 | Not known |
| CVE-2025-21335 | Microsoft | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Jan 14, 2025 | Not known |
| CVE-2023-48365 | Qlik | Qlik Sense HTTP Tunneling Vulnerability | Severity: Critical CVSS 9.9 | Jan 13, 2025 | Known |
| CVE-2024-12686 | BeyondTrust | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability | Severity: High CVSS 7.2 | Jan 13, 2025 | Not known |
| CVE-2025-0282 | Ivanti | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.0 | Jan 8, 2025 | Known |
| CVE-2020-2883 | Oracle | Oracle WebLogic Server Unspecified Vulnerability | Severity: Critical CVSS 9.8 | Jan 7, 2025 | Not known |
| CVE-2024-41713 | Mitel | Mitel MiCollab Path Traversal Vulnerability | Severity: Critical CVSS 9.1 | Jan 7, 2025 | Known |
| CVE-2024-55550 | Mitel | Mitel MiCollab Path Traversal Vulnerability | Severity: Informational CVSS 2.7 | Jan 7, 2025 | Known |
| CVE-2024-3393 | Palo Alto Networks | Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability | Severity: High CVSS 8.7 | Dec 30, 2024 | Not known |
| CVE-2021-44207 | Acclaim Systems | Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability | Severity: High CVSS 8.1 | Dec 23, 2024 | Not known |
| CVE-2024-12356 | BeyondTrust | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Dec 19, 2024 | Not known |
| CVE-2018-14933 | NUUO | NUUO NVRmini Devices OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Dec 18, 2024 | Not known |
| CVE-2022-23227 | NUUO | NUUO NVRmini2 Devices Missing Authentication Vulnerability | Severity: Critical CVSS 9.8 | Dec 18, 2024 | Not known |
| CVE-2019-11001 | Reolink | Reolink Multiple IP Cameras OS Command Injection Vulnerability | Severity: High CVSS 7.2 | Dec 18, 2024 | Not known |
| CVE-2021-40407 | Reolink | Reolink RLC-410W IP Camera OS Command Injection Vulnerability | Severity: High CVSS 7.2 | Dec 18, 2024 | Not known |
| CVE-2024-55956 | Cleo | Cleo Multiple Products Unauthenticated File Upload Vulnerability | Severity: Critical CVSS 9.8 | Dec 17, 2024 | Known |
| CVE-2024-35250 | Microsoft | Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability | Severity: High CVSS 7.8 | Dec 16, 2024 | Not known |
| CVE-2024-20767 | Adobe | Adobe ColdFusion Improper Access Control Vulnerability | Severity: High CVSS 7.4 | Dec 16, 2024 | Not known |
| CVE-2024-50623 | Cleo | Cleo Multiple Products Unrestricted File Upload Vulnerability | Severity: Critical CVSS 9.8 | Dec 13, 2024 | Known |
| CVE-2024-49138 | Microsoft | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Dec 10, 2024 | Not known |
| CVE-2024-51378 | CyberPersons | CyberPanel Incorrect Default Permissions Vulnerability | Severity: Critical CVSS 9.8 | Dec 4, 2024 | Known |
| CVE-2024-11667 | Zyxel | Zyxel Multiple Firewalls Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Dec 3, 2024 | Known |
| CVE-2024-11680 | ProjectSend | ProjectSend Improper Authentication Vulnerability | Severity: Critical CVSS 9.8 | Dec 3, 2024 | Not known |
| CVE-2023-45727 | North Grid | North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability | Severity: High CVSS 7.5 | Dec 3, 2024 | Not known |
| CVE-2023-28461 | Array Networks | Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability | Severity: Critical CVSS 9.8 | Nov 25, 2024 | Known |
| CVE-2024-44308 | Apple | Apple Multiple Products Code Execution Vulnerability | Severity: High CVSS 8.8 | Nov 21, 2024 | Not known |
| CVE-2024-21287 | Oracle | Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability | Severity: High CVSS 7.5 | Nov 21, 2024 | Not known |
| CVE-2024-44309 | Apple | Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.3 | Nov 21, 2024 | Not known |
| CVE-2024-38812 | VMware | VMware vCenter Server Heap-Based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Nov 20, 2024 | Not known |
| CVE-2024-38813 | VMware | VMware vCenter Server Privilege Escalation Vulnerability | Severity: Critical CVSS 9.8 | Nov 20, 2024 | Not known |
| CVE-2024-1212 | Progress | Progress Kemp LoadMaster OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Nov 18, 2024 | Not known |
| CVE-2024-0012 | Palo Alto Networks | Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability | Severity: Critical CVSS 9.3 | Nov 18, 2024 | Known |
| CVE-2024-9474 | Palo Alto Networks | Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability | Severity: Elevated CVSS 6.9 | Nov 18, 2024 | Known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
