Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2024-9463 | Palo Alto Networks | Palo Alto Networks Expedition OS Command Injection Vulnerability | Severity: Critical CVSS 9.9 | Nov 14, 2024 | Not known |
| CVE-2024-9465 | Palo Alto Networks | Palo Alto Networks Expedition SQL Injection Vulnerability | Severity: Critical CVSS 9.2 | Nov 14, 2024 | Not known |
| CVE-2024-49039 | Microsoft | Microsoft Windows Task Scheduler Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | Nov 12, 2024 | Known |
| CVE-2021-41277 | Metabase | Metabase GeoJSON API Local File Inclusion Vulnerability | Severity: High CVSS 7.5 | Nov 12, 2024 | Not known |
| CVE-2024-43451 | Microsoft | Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability | Severity: Elevated CVSS 6.5 | Nov 12, 2024 | Not known |
| CVE-2014-2120 | Cisco | Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Nov 12, 2024 | Not known |
| CVE-2021-26086 | Atlassian | Atlassian Jira Server and Data Center Path Traversal Vulnerability | Severity: Elevated CVSS 5.3 | Nov 12, 2024 | Not known |
| CVE-2019-16278 | Nostromo | Nostromo nhttpd Directory Traversal Vulnerability | Severity: Critical CVSS 9.8 | Nov 7, 2024 | Not known |
| CVE-2024-51567 | CyberPersons | CyberPanel Incorrect Default Permissions Vulnerability | Severity: Critical CVSS 9.8 | Nov 7, 2024 | Known |
| CVE-2024-5910 | Palo Alto Networks | Palo Alto Networks Expedition Missing Authentication Vulnerability | Severity: Critical CVSS 9.3 | Nov 7, 2024 | Not known |
| CVE-2024-43093 | Android | Android Framework Privilege Escalation Vulnerability | Severity: High CVSS 7.3 | Nov 7, 2024 | Not known |
| CVE-2024-8956 | PTZOptics | PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability | Severity: Critical CVSS 9.1 | Nov 4, 2024 | Not known |
| CVE-2024-8957 | PTZOptics | PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability | Severity: High CVSS 7.2 | Nov 4, 2024 | Not known |
| CVE-2024-37383 | Roundcube | RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Oct 24, 2024 | Not known |
| CVE-2024-20481 | Cisco | Cisco ASA and FTD Denial-of-Service Vulnerability | Severity: Elevated CVSS 5.8 | Oct 24, 2024 | Not known |
| CVE-2024-47575 | Fortinet | Fortinet FortiManager Missing Authentication Vulnerability | Severity: Critical CVSS 9.8 | Oct 23, 2024 | Not known |
| CVE-2024-38094 | Microsoft | Microsoft SharePoint Deserialization Vulnerability | Severity: High CVSS 7.2 | Oct 22, 2024 | Known |
| CVE-2024-9537 | ScienceLogic | ScienceLogic SL1 Unspecified Vulnerability | Severity: Critical CVSS 9.3 | Oct 21, 2024 | Not known |
| CVE-2024-40711 | Veeam | Veeam Backup and Replication Deserialization Vulnerability | Severity: Critical CVSS 9.8 | Oct 17, 2024 | Known |
| CVE-2024-9680 | Mozilla | Mozilla Firefox Use-After-Free Vulnerability | Severity: Critical CVSS 9.8 | Oct 15, 2024 | Known |
| CVE-2024-28987 | SolarWinds | SolarWinds Web Help Desk Hardcoded Credential Vulnerability | Severity: Critical CVSS 9.1 | Oct 15, 2024 | Not known |
| CVE-2024-30088 | Microsoft | Microsoft Windows Kernel TOCTOU Race Condition Vulnerability | Severity: High CVSS 7.0 | Oct 15, 2024 | Known |
| CVE-2024-23113 | Fortinet | Fortinet Multiple Products Format String Vulnerability | Severity: Critical CVSS 9.8 | Oct 9, 2024 | Not known |
| CVE-2024-9379 | Ivanti | Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability | Severity: High CVSS 7.2 | Oct 9, 2024 | Not known |
| CVE-2024-9380 | Ivanti | Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability | Severity: High CVSS 7.2 | Oct 9, 2024 | Not known |
| CVE-2024-43573 | Microsoft | Microsoft Windows MSHTML Platform Spoofing Vulnerability | Severity: High CVSS 8.1 | Oct 8, 2024 | Not known |
| CVE-2024-43047 | Qualcomm | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Oct 8, 2024 | Not known |
| CVE-2024-43572 | Microsoft | Microsoft Windows Management Console Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Oct 8, 2024 | Not known |
| CVE-2024-45519 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability | Severity: Critical CVSS 9.8 | Oct 3, 2024 | Not known |
| CVE-2024-29824 | Ivanti | Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability | Severity: High CVSS 8.8 | Oct 2, 2024 | Not known |
| CVE-2019-0344 | SAP | SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Sep 30, 2024 | Not known |
| CVE-2020-15415 | DrayTek | DrayTek Multiple Vigor Routers OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Sep 30, 2024 | Not known |
| CVE-2023-25280 | D-Link | D-Link DIR-820 Router OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Sep 30, 2024 | Not known |
| CVE-2024-7593 | Ivanti | Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Sep 24, 2024 | Not known |
| CVE-2024-8963 | Ivanti | Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability | Severity: Critical CVSS 9.1 | Sep 19, 2024 | Not known |
| CVE-2020-14644 | Oracle | Oracle WebLogic Server Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Sep 18, 2024 | Not known |
| CVE-2022-21445 | Oracle | Oracle ADF Faces Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Sep 18, 2024 | Not known |
| CVE-2024-27348 | Apache | Apache HugeGraph-Server Improper Access Control Vulnerability | Severity: Critical CVSS 9.8 | Sep 18, 2024 | Not known |
| CVE-2020-0618 | Microsoft | Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Sep 18, 2024 | Known |
| CVE-2014-0497 | Adobe | Adobe Flash Player Integer Underflow Vulnerablity | Severity: Critical CVSS 9.8 | Sep 17, 2024 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
