Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2023-41763 | Microsoft | Microsoft Skype for Business Privilege Escalation Vulnerability | Severity: Elevated CVSS 5.3 | Oct 10, 2023 | Not known |
| CVE-2023-22515 | Atlassian | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability | Severity: Critical CVSS 9.8 | Oct 5, 2023 | Known |
| CVE-2023-40044 | Progress | Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability | Severity: High CVSS 8.8 | Oct 5, 2023 | Known |
| CVE-2023-42824 | Apple | Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Oct 5, 2023 | Not known |
| CVE-2023-42793 | JetBrains | JetBrains TeamCity Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Oct 4, 2023 | Known |
| CVE-2023-28229 | Microsoft | Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability | Severity: High CVSS 7.0 | Oct 4, 2023 | Not known |
| CVE-2023-4211 | Arm | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | Severity: Elevated CVSS 5.5 | Oct 3, 2023 | Not known |
| CVE-2023-5217 | Google Chromium libvpx Heap Buffer Overflow Vulnerability | Severity: High CVSS 8.8 | Oct 2, 2023 | Not known | |
| CVE-2018-14667 | Red Hat | Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability | Severity: Critical CVSS 9.8 | Sep 28, 2023 | Not known |
| CVE-2023-41993 | Apple | Apple Multiple Products WebKit Code Execution Vulnerability | Severity: High CVSS 8.8 | Sep 25, 2023 | Not known |
| CVE-2023-41992 | Apple | Apple Multiple Products Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Sep 25, 2023 | Not known |
| CVE-2023-41991 | Apple | Apple Multiple Products Improper Certificate Validation Vulnerability | Severity: Elevated CVSS 5.5 | Sep 25, 2023 | Not known |
| CVE-2023-41179 | Trend Micro | Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability | Severity: High CVSS 7.2 | Sep 21, 2023 | Not known |
| CVE-2023-28434 | MinIO | MinIO Security Feature Bypass Vulnerability | Severity: High CVSS 8.8 | Sep 19, 2023 | Not known |
| CVE-2014-8361 | Realtek | Realtek SDK Improper Input Validation Vulnerability | Severity: Critical CVSS 9.8 | Sep 18, 2023 | Not known |
| CVE-2021-3129 | Laravel | Laravel Ignition File Upload Vulnerability | Severity: Critical CVSS 9.8 | Sep 18, 2023 | Known |
| CVE-2017-6884 | Zyxel | Zyxel EMG2926 Routers Command Injection Vulnerability | Severity: High CVSS 8.8 | Sep 18, 2023 | Known |
| CVE-2022-22265 | Samsung | Samsung Mobile Devices Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Sep 18, 2023 | Not known |
| CVE-2023-26369 | Adobe | Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability | Severity: High CVSS 7.8 | Sep 14, 2023 | Not known |
| CVE-2023-20269 | Cisco | Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability | Severity: Critical CVSS 9.1 | Sep 13, 2023 | Known |
| CVE-2023-4863 | Google Chromium WebP Heap-Based Buffer Overflow Vulnerability | Severity: High CVSS 8.8 | Sep 13, 2023 | Not known | |
| CVE-2023-35674 | Android | Android Framework Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Sep 13, 2023 | Not known |
| CVE-2023-36802 | Microsoft | Microsoft Streaming Service Proxy Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Sep 12, 2023 | Not known |
| CVE-2023-36761 | Microsoft | Microsoft Word Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | Sep 12, 2023 | Not known |
| CVE-2023-41061 | Apple | Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability | Severity: High CVSS 7.8 | Sep 11, 2023 | Not known |
| CVE-2023-41064 | Apple | Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Sep 11, 2023 | Not known |
| CVE-2023-33246 | Apache | Apache RocketMQ Command Execution Vulnerability | Severity: Critical CVSS 9.8 | Sep 6, 2023 | Not known |
| CVE-2023-38831 | RARLAB | RARLAB WinRAR Code Execution Vulnerability | Severity: High CVSS 7.8 | Aug 24, 2023 | Known |
| CVE-2023-32315 | Ignite Realtime | Ignite Realtime Openfire Path Traversal Vulnerability | Severity: High CVSS 7.5 | Aug 24, 2023 | Not known |
| CVE-2023-38035 | Ivanti | Ivanti Sentry Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Aug 22, 2023 | Known |
| CVE-2023-27532 | Veeam | Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability | Severity: High CVSS 7.5 | Aug 22, 2023 | Known |
| CVE-2023-26359 | Adobe | Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Aug 21, 2023 | Not known |
| CVE-2023-24489 | Citrix | Citrix Content Collaboration ShareFile Improper Access Control Vulnerability | Severity: Critical CVSS 9.8 | Aug 16, 2023 | Not known |
| CVE-2023-38180 | Microsoft | Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability | Severity: High CVSS 7.5 | Aug 9, 2023 | Not known |
| CVE-2017-18368 | Zyxel | Zyxel P660HN-T1A Routers Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Aug 7, 2023 | Not known |
| CVE-2023-35081 | Ivanti | Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability | Severity: High CVSS 7.2 | Jul 31, 2023 | Not known |
| CVE-2023-37580 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Jul 27, 2023 | Not known |
| CVE-2023-38606 | Apple | Apple Multiple Products Kernel Unspecified Vulnerability | Severity: Elevated CVSS 5.5 | Jul 26, 2023 | Not known |
| CVE-2023-35078 | Ivanti | Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Jul 25, 2023 | Known |
| CVE-2023-29298 | Adobe | Adobe ColdFusion Improper Access Control Vulnerability | Severity: High CVSS 7.5 | Jul 20, 2023 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
