Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2026-49869 | Kestra | Kestra OSS OS Command Injection Vulnerability | Severity: Critical CVSS 10.0 | Sep 2, 2026 | Not known |
| CVE-2026-83548 | SonicWall | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | Severity: Critical CVSS 10.0 | Sep 2, 2026 | Not known |
| CVE-2026-82329 | JFrog | JFrog Artifactory Improper Authentication Vulnerability | Severity: Critical CVSS 9.8 | Sep 2, 2026 | Not known |
| CVE-2026-9586 | Sangoma | Sangoma Switchvox SQL Injection Vulnerability | Severity: Critical CVSS 9.3 | Sep 2, 2026 | Not known |
| CVE-2026-59822 | BerriAI | BerriAI LiteLLM Improper Authentication Vulnerability | Severity: High CVSS 8.8 | Sep 2, 2026 | Not known |
| CVE-2026-83549 | SonicWall | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | Severity: High CVSS 7.8 | Sep 2, 2026 | Not known |
| CVE-2026-48710 | Kludex | Kludex Starlette HTTP Request/Response Smuggling Vulnerability | Severity: Elevated CVSS 6.5 | Sep 2, 2026 | Not known |
| CVE-2026-82078 | PaperCut | PaperCut NG/MF Unsafe Reflection Vulnerability | Severity: Critical CVSS 9.4 | Aug 31, 2026 | Not known |
| CVE-2026-81578 | PaperCut | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability | Severity: High CVSS 8.8 | Aug 31, 2026 | Not known |
| CVE-2023-49105 | ownCloud | ownCloud Improper Authentication Vulnerability | Severity: Critical CVSS 9.8 | Aug 27, 2026 | Not known |
| CVE-2026-53362 | Linux | Linux Kernel Unspecified Vulnerability | Severity: High CVSS 7.8 | Aug 27, 2026 | Not known |
| CVE-2026-66384 | JFrog | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | Severity: Elevated CVSS 5.3 | Aug 27, 2026 | Not known |
| CVE-2021-23758 | Ajax.NET Professional | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Aug 26, 2026 | Not known |
| CVE-2019-1068 | Microsoft | Microsoft SQL Server Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Aug 26, 2026 | Not known |
| CVE-2026-8452 | Citrix | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | Severity: High CVSS 8.8 | Aug 26, 2026 | Not known |
| CVE-2015-5287 | Red Hat | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Aug 26, 2026 | Not known |
| CVE-2022-0995 | Linux | Linux Kernel Out-of-Bounds Write Vulnerability | Severity: High CVSS 7.8 | Aug 26, 2026 | Not known |
| CVE-2015-3246 | Red Hat | Red Hat Libuser Race Condition Vulnerability | Severity: Elevated CVSS 5.1 | Aug 26, 2026 | Not known |
| CVE-2026-60004 | Gitea | Gitea Code Injection Vulnerability | Severity: Critical CVSS 9.8 | Aug 25, 2026 | Not known |
| CVE-2026-21962 | Oracle | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | Severity: Critical CVSS 10.0 | Aug 24, 2026 | Not known |
| CVE-2026-73570 | Synacor | Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability | Severity: High CVSS 8.9 | Aug 21, 2026 | Not known |
| CVE-2026-72530 | TrueConf | TrueConf Server Code Injection Vulnerability | Severity: Critical CVSS 9.5 | Aug 20, 2026 | Not known |
| CVE-2026-72529 | TrueConf | TrueConf Server Missing Authentication for Critical Function Vulnerability | Severity: Critical CVSS 9.3 | Aug 20, 2026 | Not known |
| CVE-2026-64849 | MLflow | MLflow Server-Side Request Forgery Vulnerability | Severity: Critical CVSS 9.3 | Aug 19, 2026 | Not known |
| CVE-2026-33824 | Microsoft | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | Severity: Critical CVSS 9.8 | Aug 18, 2026 | Not known |
| CVE-2026-59310 | Broadcom | Broadcom VMware vCenter Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Aug 18, 2026 | Known |
| CVE-2026-65400 | Apple | Apple macOS Improper Authentication Vulnerability | Severity: Critical CVSS 9.8 | Aug 18, 2026 | Not known |
| CVE-2026-55040 | Microsoft | Microsoft SharePoint Weak Authentication Vulnerability | Severity: Critical CVSS 9.1 | Aug 18, 2026 | Not known |
| CVE-2025-62593 | Ray-Project | Ray-Project Ray Code Injection Vulnerability | Severity: Critical CVSS 9.4 | Aug 17, 2026 | Not known |
| CVE-2026-72898 | Metabase | Metabase SQL Injection Vulnerability | Severity: Critical CVSS 10.0 | Aug 11, 2026 | Not known |
| CVE-2026-20349 | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability | Severity: High CVSS 8.6 | Aug 11, 2026 | Not known |
| CVE-2026-68820 | Microsoft | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | Severity: High CVSS 7.0 | Aug 11, 2026 | Not known |
| CVE-2026-8037 | Progress | Progress LoadMaster Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Aug 7, 2026 | Not known |
| CVE-2026-63077 | JetBrains | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Aug 5, 2026 | Known |
| CVE-2026-9198 | IBM | IBM Langflow Code Injection Vulnerability | Severity: Critical CVSS 9.8 | Aug 4, 2026 | Not known |
| CVE-2026-18556 | N-able | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | Severity: High CVSS 8.2 | Aug 4, 2026 | Not known |
| CVE-2026-34486 | Apache | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | Severity: High CVSS 7.5 | Aug 4, 2026 | Not known |
| CVE-2026-18577 | N-able | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | Severity: High CVSS 8.2 | Aug 3, 2026 | Not known |
| CVE-2026-20316 | Cisco | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | Severity: Elevated CVSS 5.3 | Jul 29, 2026 | Known |
| CVE-2026-16812 | Arista | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | Severity: Critical CVSS 10.0 | Jul 27, 2026 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
