Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2013-0643 | Adobe | Adobe Flash Player Incorrect Default Permissions Vulnerability | Severity: High CVSS 8.8 | Sep 17, 2024 | Not known |
| CVE-2013-0648 | Adobe | Adobe Flash Player Code Execution Vulnerability | Severity: High CVSS 8.8 | Sep 17, 2024 | Not known |
| CVE-2014-0502 | Adobe | Adobe Flash Player Double Free Vulnerablity | Severity: High CVSS 8.8 | Sep 17, 2024 | Not known |
| CVE-2024-6670 | Progress | Progress WhatsUp Gold SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Sep 16, 2024 | Known |
| CVE-2024-43461 | Microsoft | Microsoft Windows MSHTML Platform Spoofing Vulnerability | Severity: High CVSS 8.8 | Sep 16, 2024 | Not known |
| CVE-2024-8190 | Ivanti | Ivanti Cloud Services Appliance OS Command Injection Vulnerability | Severity: High CVSS 7.2 | Sep 13, 2024 | Not known |
| CVE-2024-38014 | Microsoft | Microsoft Windows Installer Improper Privilege Management Vulnerability | Severity: High CVSS 7.8 | Sep 10, 2024 | Not known |
| CVE-2024-38226 | Microsoft | Microsoft Publisher Protection Mechanism Failure Vulnerability | Severity: High CVSS 7.3 | Sep 10, 2024 | Not known |
| CVE-2024-38217 | Microsoft | Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability | Severity: Elevated CVSS 5.4 | Sep 10, 2024 | Not known |
| CVE-2024-40766 | SonicWall | SonicWall SonicOS Improper Access Control Vulnerability | Severity: Critical CVSS 9.8 | Sep 9, 2024 | Known |
| CVE-2016-3714 | ImageMagick | ImageMagick Improper Input Validation Vulnerability | Severity: High CVSS 8.4 | Sep 9, 2024 | Not known |
| CVE-2017-1000253 | Linux | Linux Kernel PIE Stack Buffer Corruption Vulnerability | Severity: High CVSS 7.8 | Sep 9, 2024 | Known |
| CVE-2024-7262 | Kingsoft | Kingsoft WPS Office Path Traversal Vulnerability | Severity: Critical CVSS 9.3 | Sep 3, 2024 | Not known |
| CVE-2021-20123 | DrayTek | Draytek VigorConnect Path Traversal Vulnerability | Severity: High CVSS 7.5 | Sep 3, 2024 | Not known |
| CVE-2021-20124 | DrayTek | Draytek VigorConnect Path Traversal Vulnerability | Severity: High CVSS 7.5 | Sep 3, 2024 | Not known |
| CVE-2024-7965 | Google Chromium V8 Inappropriate Implementation Vulnerability | Severity: High CVSS 8.8 | Aug 28, 2024 | Not known | |
| CVE-2024-38856 | Apache | Apache OFBiz Incorrect Authorization Vulnerability | Severity: Critical CVSS 9.8 | Aug 27, 2024 | Not known |
| CVE-2024-7971 | Google Chromium V8 Type Confusion Vulnerability | Severity: Critical CVSS 9.6 | Aug 26, 2024 | Not known | |
| CVE-2024-39717 | Versa | Versa Director Dangerous File Type Upload Vulnerability | Severity: High CVSS 7.2 | Aug 23, 2024 | Not known |
| CVE-2021-33044 | Dahua | Dahua IP Camera Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Aug 21, 2024 | Not known |
| CVE-2021-33045 | Dahua | Dahua IP Camera Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Aug 21, 2024 | Not known |
| CVE-2022-0185 | Linux | Linux Kernel Heap-Based Buffer Overflow Vulnerability | Severity: High CVSS 8.4 | Aug 21, 2024 | Not known |
| CVE-2021-31196 | Microsoft | Microsoft Exchange Server Information Disclosure Vulnerability | Severity: High CVSS 7.2 | Aug 21, 2024 | Not known |
| CVE-2024-23897 | Jenkins | Jenkins Command Line Interface (CLI) Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Aug 19, 2024 | Known |
| CVE-2024-28986 | SolarWinds | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Aug 15, 2024 | Not known |
| CVE-2024-38189 | Microsoft | Microsoft Project Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Aug 13, 2024 | Not known |
| CVE-2024-38107 | Microsoft | Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Aug 13, 2024 | Not known |
| CVE-2024-38193 | Microsoft | Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Aug 13, 2024 | Not known |
| CVE-2024-38178 | Microsoft | Microsoft Windows Scripting Engine Memory Corruption Vulnerability | Severity: High CVSS 7.5 | Aug 13, 2024 | Not known |
| CVE-2024-38106 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.0 | Aug 13, 2024 | Not known |
| CVE-2024-38213 | Microsoft | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | Severity: Elevated CVSS 6.5 | Aug 13, 2024 | Not known |
| CVE-2024-32113 | Apache | Apache OFBiz Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Aug 7, 2024 | Not known |
| CVE-2024-36971 | Android | Android Kernel Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Aug 7, 2024 | Not known |
| CVE-2018-0824 | Microsoft | Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability | Severity: High CVSS 8.8 | Aug 5, 2024 | Not known |
| CVE-2024-37085 | VMware | VMware ESXi Authentication Bypass Vulnerability | Severity: High CVSS 7.2 | Jul 30, 2024 | Known |
| CVE-2023-45249 | Acronis | Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability | Severity: Critical CVSS 9.8 | Jul 29, 2024 | Not known |
| CVE-2024-4879 | ServiceNow | ServiceNow Improper Input Validation Vulnerability | Severity: Critical CVSS 9.3 | Jul 29, 2024 | Not known |
| CVE-2024-5217 | ServiceNow | ServiceNow Incomplete List of Disallowed Inputs Vulnerability | Severity: Critical CVSS 9.2 | Jul 29, 2024 | Not known |
| CVE-2012-4792 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Jul 23, 2024 | Not known |
| CVE-2024-39891 | Twilio | Twilio Authy Information Disclosure Vulnerability | Severity: Elevated CVSS 5.3 | Jul 23, 2024 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
