Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2024-34102 | Adobe | Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability | Severity: Critical CVSS 9.8 | Jul 17, 2024 | Not known |
| CVE-2024-28995 | SolarWinds | SolarWinds Serv-U Path Traversal Vulnerability | Severity: High CVSS 7.5 | Jul 17, 2024 | Not known |
| CVE-2022-22948 | VMware | VMware vCenter Server Incorrect Default File Permissions Vulnerability | Severity: Elevated CVSS 6.5 | Jul 17, 2024 | Not known |
| CVE-2024-36401 | OSGeo | OSGeo GeoServer GeoTools Eval Injection Vulnerability | Severity: Critical CVSS 9.8 | Jul 15, 2024 | Not known |
| CVE-2024-23692 | Rejetto | Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability | Severity: Critical CVSS 9.8 | Jul 9, 2024 | Known |
| CVE-2024-38080 | Microsoft | Microsoft Windows Hyper-V Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jul 9, 2024 | Not known |
| CVE-2024-38112 | Microsoft | Microsoft Windows MSHTML Platform Spoofing Vulnerability | Severity: High CVSS 7.5 | Jul 9, 2024 | Not known |
| CVE-2024-20399 | Cisco | Cisco NX-OS Command Injection Vulnerability | Severity: Elevated CVSS 6.7 | Jul 2, 2024 | Not known |
| CVE-2022-24816 | OSGeo | OSGeo GeoServer JAI-EXT Code Injection Vulnerability | Severity: Critical CVSS 10.0 | Jun 26, 2024 | Not known |
| CVE-2022-2586 | Linux | Linux Kernel Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Jun 26, 2024 | Not known |
| CVE-2020-13965 | Roundcube | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Jun 26, 2024 | Not known |
| CVE-2024-4358 | Progress | Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability | Severity: Critical CVSS 9.8 | Jun 13, 2024 | Not known |
| CVE-2024-26169 | Microsoft | Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability | Severity: High CVSS 7.8 | Jun 13, 2024 | Known |
| CVE-2024-32896 | Android | Android Pixel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jun 13, 2024 | Not known |
| CVE-2024-4577 | PHP Group | PHP-CGI OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Jun 12, 2024 | Known |
| CVE-2024-4610 | Arm | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Jun 12, 2024 | Not known |
| CVE-2017-3506 | Oracle | Oracle WebLogic Server OS Command Injection Vulnerability | Severity: High CVSS 7.4 | Jun 3, 2024 | Not known |
| CVE-2024-24919 | Check Point | Check Point Quantum Security Gateways Information Disclosure Vulnerability | Severity: High CVSS 8.6 | May 30, 2024 | Known |
| CVE-2024-1086 | Linux | Linux Kernel Use-After-Free Vulnerability | Severity: High CVSS 7.8 | May 30, 2024 | Known |
| CVE-2024-4978 | Justice AV Solutions | Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability | Severity: High CVSS 8.7 | May 29, 2024 | Not known |
| CVE-2024-5274 | Google Chromium V8 Type Confusion Vulnerability | Severity: Critical CVSS 9.6 | May 28, 2024 | Not known | |
| CVE-2020-17519 | Apache | Apache Flink Improper Access Control Vulnerability | Severity: High CVSS 7.5 | May 23, 2024 | Not known |
| CVE-2023-43208 | NextGen Healthcare | NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | May 20, 2024 | Known |
| CVE-2024-4947 | Google Chromium V8 Type Confusion Vulnerability | Severity: Critical CVSS 9.6 | May 20, 2024 | Not known | |
| CVE-2024-4761 | Google Chromium V8 Out-of-Bounds Memory Write Vulnerability | Severity: High CVSS 8.8 | May 16, 2024 | Not known | |
| CVE-2014-100005 | D-Link | D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability | Severity: High CVSS 8.0 | May 16, 2024 | Not known |
| CVE-2021-40655 | D-Link | D-Link DIR-605 Router Information Disclosure Vulnerability | Severity: High CVSS 7.5 | May 16, 2024 | Not known |
| CVE-2024-30040 | Microsoft | Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability | Severity: High CVSS 8.8 | May 14, 2024 | Not known |
| CVE-2024-30051 | Microsoft | Microsoft DWM Core Library Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 14, 2024 | Known |
| CVE-2024-4671 | Google Chromium Visuals Use-After-Free Vulnerability | Severity: Critical CVSS 9.6 | May 13, 2024 | Not known | |
| CVE-2023-7028 | GitLab | GitLab Community and Enterprise Editions Improper Access Control Vulnerability | Severity: Critical CVSS 9.8 | May 1, 2024 | Not known |
| CVE-2024-29988 | Microsoft | Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability | Severity: High CVSS 8.8 | Apr 30, 2024 | Not known |
| CVE-2024-4040 | CrushFTP | CrushFTP VFS Sandbox Escape Vulnerability | Severity: Critical CVSS 10.0 | Apr 24, 2024 | Not known |
| CVE-2024-20353 | Cisco | Cisco ASA and FTD Denial of Service Vulnerability | Severity: High CVSS 8.6 | Apr 24, 2024 | Not known |
| CVE-2024-20359 | Cisco | Cisco ASA and FTD Privilege Escalation Vulnerability | Severity: Elevated CVSS 6.0 | Apr 24, 2024 | Not known |
| CVE-2022-38028 | Microsoft | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 23, 2024 | Not known |
| CVE-2024-3400 | Palo Alto Networks | Palo Alto Networks PAN-OS Command Injection Vulnerability | Severity: Critical CVSS 10.0 | Apr 12, 2024 | Known |
| CVE-2024-3272 | D-Link | D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability | Severity: Critical CVSS 9.8 | Apr 11, 2024 | Not known |
| CVE-2024-3273 | D-Link | D-Link Multiple NAS Devices Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Apr 11, 2024 | Not known |
| CVE-2024-29748 | Android | Android Pixel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 4, 2024 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
