Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2023-7101 | Spreadsheet::ParseExcel | Spreadsheet::ParseExcel Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Jan 2, 2024 | Not known |
| CVE-2023-47565 | QNAP | QNAP VioStor NVR OS Command Injection Vulnerability | Severity: High CVSS 8.8 | Dec 21, 2023 | Not known |
| CVE-2023-49897 | FXC | FXC AE1021, AE1021PE OS Command Injection Vulnerability | Severity: High CVSS 8.8 | Dec 21, 2023 | Not known |
| CVE-2023-6448 | Unitronics | Unitronics Vision PLC and HMI Insecure Default Password Vulnerability | Severity: Critical CVSS 9.8 | Dec 11, 2023 | Not known |
| CVE-2023-41265 | Qlik | Qlik Sense HTTP Tunneling Vulnerability | Severity: Critical CVSS 9.9 | Dec 7, 2023 | Known |
| CVE-2023-41266 | Qlik | Qlik Sense Path Traversal Vulnerability | Severity: Elevated CVSS 6.5 | Dec 7, 2023 | Known |
| CVE-2022-22071 | Qualcomm | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Dec 5, 2023 | Not known |
| CVE-2023-33063 | Qualcomm | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Dec 5, 2023 | Not known |
| CVE-2023-33106 | Qualcomm | Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability | Severity: High CVSS 7.8 | Dec 5, 2023 | Not known |
| CVE-2023-33107 | Qualcomm | Qualcomm Multiple Chipsets Integer Overflow Vulnerability | Severity: High CVSS 7.8 | Dec 5, 2023 | Not known |
| CVE-2023-42917 | Apple | Apple Multiple Products WebKit Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Dec 4, 2023 | Not known |
| CVE-2023-42916 | Apple | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | Severity: Elevated CVSS 6.5 | Dec 4, 2023 | Not known |
| CVE-2023-6345 | Google Skia Integer Overflow Vulnerability | Severity: Critical CVSS 9.6 | Nov 30, 2023 | Not known | |
| CVE-2023-49103 | ownCloud | ownCloud graphapi Information Disclosure Vulnerability | Severity: High CVSS 7.5 | Nov 30, 2023 | Not known |
| CVE-2023-4911 | GNU | GNU C Library Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Nov 21, 2023 | Not known |
| CVE-2020-2551 | Oracle | Oracle Fusion Middleware Unspecified Vulnerability | Severity: Critical CVSS 9.8 | Nov 16, 2023 | Not known |
| CVE-2023-1671 | Sophos | Sophos Web Appliance Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Nov 16, 2023 | Not known |
| CVE-2023-36584 | Microsoft | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability | Severity: Elevated CVSS 5.4 | Nov 16, 2023 | Not known |
| CVE-2023-36025 | Microsoft | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | Severity: High CVSS 8.8 | Nov 14, 2023 | Not known |
| CVE-2023-36033 | Microsoft | Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 14, 2023 | Not known |
| CVE-2023-36036 | Microsoft | Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 14, 2023 | Not known |
| CVE-2023-36845 | Juniper | Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability | Severity: Critical CVSS 9.8 | Nov 13, 2023 | Not known |
| CVE-2023-47246 | SysAid | SysAid Server Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Nov 13, 2023 | Known |
| CVE-2023-36844 | Juniper | Juniper Junos OS EX Series PHP External Variable Modification Vulnerability | Severity: Elevated CVSS 5.3 | Nov 13, 2023 | Not known |
| CVE-2023-36846 | Juniper | Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability | Severity: Elevated CVSS 5.3 | Nov 13, 2023 | Not known |
| CVE-2023-36847 | Juniper | Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability | Severity: Elevated CVSS 5.3 | Nov 13, 2023 | Not known |
| CVE-2023-36851 | Juniper | Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability | Severity: Elevated CVSS 5.3 | Nov 13, 2023 | Not known |
| CVE-2023-29552 | IETF | Service Location Protocol (SLP) Denial-of-Service Vulnerability | Severity: High CVSS 7.5 | Nov 8, 2023 | Not known |
| CVE-2023-22518 | Atlassian | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability | Severity: Critical CVSS 9.8 | Nov 7, 2023 | Known |
| CVE-2023-46604 | Apache | Apache ActiveMQ Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Nov 2, 2023 | Known |
| CVE-2023-46747 | F5 | F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Oct 31, 2023 | Known |
| CVE-2023-46748 | F5 | F5 BIG-IP Configuration Utility SQL Injection Vulnerability | Severity: High CVSS 8.8 | Oct 31, 2023 | Not known |
| CVE-2023-5631 | Roundcube | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 5.4 | Oct 26, 2023 | Not known |
| CVE-2023-20273 | Cisco | Cisco IOS XE Web UI Command Injection Vulnerability | Severity: High CVSS 7.2 | Oct 23, 2023 | Not known |
| CVE-2023-4966 | Citrix | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability | Severity: High CVSS 7.5 | Oct 18, 2023 | Known |
| CVE-2023-20198 | Cisco | Cisco IOS XE Web UI Privilege Escalation Vulnerability | Severity: Critical CVSS 10.0 | Oct 16, 2023 | Not known |
| CVE-2023-21608 | Adobe | Adobe Acrobat and Reader Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Oct 10, 2023 | Not known |
| CVE-2023-44487 | IETF | HTTP/2 Rapid Reset Attack Vulnerability | Severity: High CVSS 7.5 | Oct 10, 2023 | Not known |
| CVE-2023-20109 | Cisco | Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability | Severity: Elevated CVSS 6.6 | Oct 10, 2023 | Not known |
| CVE-2023-36563 | Microsoft | Microsoft WordPad Information Disclosure Vulnerability | Severity: Elevated CVSS 5.5 | Oct 10, 2023 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
