Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2024-29745 | Android | Android Pixel Information Disclosure Vulnerability | Severity: Elevated CVSS 5.5 | Apr 4, 2024 | Not known |
| CVE-2023-24955 | Microsoft | Microsoft SharePoint Server Code Injection Vulnerability | Severity: High CVSS 7.2 | Mar 26, 2024 | Known |
| CVE-2019-7256 | Nice | Nice Linear eMerge E3-Series OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Mar 25, 2024 | Not known |
| CVE-2021-44529 | Ivanti | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability | Severity: Critical CVSS 9.8 | Mar 25, 2024 | Known |
| CVE-2023-48788 | Fortinet | Fortinet FortiClient EMS SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Mar 25, 2024 | Known |
| CVE-2024-27198 | JetBrains | JetBrains TeamCity Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Mar 7, 2024 | Known |
| CVE-2024-23225 | Apple | Apple Multiple Products Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Mar 6, 2024 | Not known |
| CVE-2024-23296 | Apple | Apple Multiple Products Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Mar 6, 2024 | Not known |
| CVE-2021-36380 | Sunhillo | Sunhillo SureLine OS Command Injection Vulnerablity | Severity: Critical CVSS 9.8 | Mar 5, 2024 | Not known |
| CVE-2023-21237 | Android | Android Pixel Information Disclosure Vulnerability | Severity: Elevated CVSS 5.5 | Mar 5, 2024 | Not known |
| CVE-2024-21338 | Microsoft | Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability | Severity: High CVSS 7.8 | Mar 4, 2024 | Known |
| CVE-2023-29360 | Microsoft | Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability | Severity: High CVSS 8.4 | Feb 29, 2024 | Not known |
| CVE-2024-1709 | ConnectWise | ConnectWise ScreenConnect Authentication Bypass Vulnerability | Severity: Critical CVSS 10.0 | Feb 22, 2024 | Known |
| CVE-2024-21410 | Microsoft | Microsoft Exchange Server Privilege Escalation Vulnerability | Severity: Critical CVSS 9.8 | Feb 15, 2024 | Not known |
| CVE-2020-3259 | Cisco | Cisco ASA and FTD Information Disclosure Vulnerability | Severity: High CVSS 7.5 | Feb 15, 2024 | Known |
| CVE-2024-21412 | Microsoft | Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability | Severity: High CVSS 8.1 | Feb 13, 2024 | Known |
| CVE-2024-21351 | Microsoft | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | Severity: High CVSS 7.6 | Feb 13, 2024 | Not known |
| CVE-2023-43770 | Roundcube | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Feb 12, 2024 | Not known |
| CVE-2024-21762 | Fortinet | Fortinet FortiOS Out-of-Bound Write Vulnerability | Severity: Critical CVSS 9.8 | Feb 9, 2024 | Known |
| CVE-2023-4762 | Google Chromium V8 Type Confusion Vulnerability | Severity: High CVSS 8.8 | Feb 6, 2024 | Not known | |
| CVE-2024-21893 | Ivanti | Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability | Severity: High CVSS 8.2 | Jan 31, 2024 | Known |
| CVE-2022-48618 | Apple | Apple Multiple Products Memory Corruption Vulnerability | Severity: High CVSS 7.0 | Jan 31, 2024 | Not known |
| CVE-2023-22527 | Atlassian | Atlassian Confluence Data Center and Server Template Injection Vulnerability | Severity: Critical CVSS 9.8 | Jan 24, 2024 | Known |
| CVE-2024-23222 | Apple | Apple Multiple Products WebKit Type Confusion Vulnerability | Severity: High CVSS 8.8 | Jan 23, 2024 | Not known |
| CVE-2023-34048 | VMware | VMware vCenter Server Out-of-Bounds Write Vulnerability | Severity: Critical CVSS 9.8 | Jan 22, 2024 | Not known |
| CVE-2023-35082 | Ivanti | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Jan 18, 2024 | Known |
| CVE-2023-6548 | Citrix | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | Severity: High CVSS 8.8 | Jan 17, 2024 | Not known |
| CVE-2024-0519 | Google Chromium V8 Out-of-Bounds Memory Access Vulnerability | Severity: High CVSS 8.8 | Jan 17, 2024 | Not known | |
| CVE-2023-6549 | Citrix | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | Severity: High CVSS 7.5 | Jan 17, 2024 | Not known |
| CVE-2018-15133 | Laravel | Laravel Deserialization of Untrusted Data Vulnerability | Severity: High CVSS 8.1 | Jan 16, 2024 | Not known |
| CVE-2023-29357 | Microsoft | Microsoft SharePoint Server Privilege Escalation Vulnerability | Severity: Critical CVSS 9.8 | Jan 10, 2024 | Known |
| CVE-2024-21887 | Ivanti | Ivanti Connect Secure and Policy Secure Command Injection Vulnerability | Severity: Critical CVSS 9.1 | Jan 10, 2024 | Known |
| CVE-2023-46805 | Ivanti | Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability | Severity: High CVSS 8.2 | Jan 10, 2024 | Known |
| CVE-2016-20017 | D-Link | D-Link DSL-2750B Devices Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Jan 8, 2024 | Not known |
| CVE-2023-27524 | Apache | Apache Superset Insecure Default Initialization of Resource Vulnerability | Severity: Critical CVSS 9.8 | Jan 8, 2024 | Not known |
| CVE-2023-29300 | Adobe | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Jan 8, 2024 | Known |
| CVE-2023-38203 | Adobe | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Jan 8, 2024 | Known |
| CVE-2023-41990 | Apple | Apple Multiple Products Code Execution Vulnerability | Severity: High CVSS 7.8 | Jan 8, 2024 | Not known |
| CVE-2023-23752 | Joomla! | Joomla! Improper Access Control Vulnerability | Severity: Elevated CVSS 5.3 | Jan 8, 2024 | Not known |
| CVE-2023-7024 | Google Chromium WebRTC Heap Buffer Overflow Vulnerability | Severity: High CVSS 8.8 | Jan 2, 2024 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
