Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2023-38205 | Adobe | Adobe ColdFusion Improper Access Control Vulnerability | Severity: High CVSS 7.5 | Jul 20, 2023 | Not known |
| CVE-2023-3519 | Citrix | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | Severity: Critical CVSS 9.8 | Jul 19, 2023 | Known |
| CVE-2023-36884 | Microsoft | Microsoft Windows Search Remote Code Execution Vulnerability | Severity: High CVSS 7.5 | Jul 17, 2023 | Known |
| CVE-2022-29303 | SolarView | SolarView Compact Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Jul 13, 2023 | Not known |
| CVE-2023-37450 | Apple | Apple Multiple Products WebKit Code Execution Vulnerability | Severity: High CVSS 8.8 | Jul 13, 2023 | Not known |
| CVE-2022-31199 | Netwrix | Netwrix Auditor Insecure Object Deserialization Vulnerability | Severity: Critical CVSS 9.8 | Jul 11, 2023 | Known |
| CVE-2023-32049 | Microsoft | Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability | Severity: High CVSS 8.8 | Jul 11, 2023 | Not known |
| CVE-2023-35311 | Microsoft | Microsoft Outlook Security Feature Bypass Vulnerability | Severity: High CVSS 8.8 | Jul 11, 2023 | Not known |
| CVE-2023-32046 | Microsoft | Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jul 11, 2023 | Not known |
| CVE-2023-36874 | Microsoft | Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jul 11, 2023 | Not known |
| CVE-2021-29256 | Arm | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Jul 7, 2023 | Not known |
| CVE-2019-17621 | D-Link | D-Link DIR-859 Router Command Execution Vulnerability | Severity: Critical CVSS 9.8 | Jun 29, 2023 | Not known |
| CVE-2019-20500 | D-Link | D-Link DWL-2600AP Access Point Command Injection Vulnerability | Severity: High CVSS 7.8 | Jun 29, 2023 | Not known |
| CVE-2021-25487 | Samsung | Samsung Mobile Devices Out-of-Bounds Read Vulnerability | Severity: High CVSS 7.8 | Jun 29, 2023 | Not known |
| CVE-2021-25371 | Samsung | Samsung Mobile Devices Unspecified Vulnerability | Severity: Elevated CVSS 6.7 | Jun 29, 2023 | Not known |
| CVE-2021-25372 | Samsung | Samsung Mobile Devices Improper Boundary Check Vulnerability | Severity: Elevated CVSS 6.7 | Jun 29, 2023 | Not known |
| CVE-2021-25394 | Samsung | Samsung Mobile Devices Race Condition Vulnerability | Severity: Elevated CVSS 6.4 | Jun 29, 2023 | Not known |
| CVE-2021-25395 | Samsung | Samsung Mobile Devices Race Condition Vulnerability | Severity: Elevated CVSS 6.4 | Jun 29, 2023 | Not known |
| CVE-2021-25489 | Samsung | Samsung Mobile Devices Improper Input Validation Vulnerability | Severity: Elevated CVSS 5.5 | Jun 29, 2023 | Not known |
| CVE-2023-27992 | Zyxel | Zyxel Multiple NAS Devices Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Jun 23, 2023 | Not known |
| CVE-2023-32435 | Apple | Apple Multiple Products WebKit Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Jun 23, 2023 | Not known |
| CVE-2023-32439 | Apple | Apple Multiple Products WebKit Type Confusion Vulnerability | Severity: High CVSS 8.8 | Jun 23, 2023 | Not known |
| CVE-2023-32434 | Apple | Apple Multiple Products Integer Overflow Vulnerability | Severity: High CVSS 7.8 | Jun 23, 2023 | Not known |
| CVE-2023-20867 | VMware | VMware Tools Authentication Bypass Vulnerability | Severity: Informational CVSS 3.9 | Jun 23, 2023 | Not known |
| CVE-2020-12641 | Roundcube | Roundcube Webmail Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Jun 22, 2023 | Not known |
| CVE-2021-44026 | Roundcube | Roundcube Webmail SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Jun 22, 2023 | Not known |
| CVE-2023-20887 | VMware | Vmware Aria Operations for Networks Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Jun 22, 2023 | Not known |
| CVE-2016-0165 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jun 22, 2023 | Not known |
| CVE-2016-9079 | Mozilla | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability | Severity: High CVSS 7.5 | Jun 22, 2023 | Not known |
| CVE-2020-35730 | Roundcube | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Jun 22, 2023 | Not known |
| CVE-2023-27997 | Fortinet | Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Jun 13, 2023 | Known |
| CVE-2023-3079 | Google Chromium V8 Type Confusion Vulnerability | Severity: High CVSS 8.8 | Jun 7, 2023 | Not known | |
| CVE-2023-33009 | Zyxel | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Jun 5, 2023 | Not known |
| CVE-2023-33010 | Zyxel | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Jun 5, 2023 | Not known |
| CVE-2023-34362 | Progress | Progress MOVEit Transfer SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Jun 2, 2023 | Known |
| CVE-2023-28771 | Zyxel | Zyxel Multiple Firewalls OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | May 31, 2023 | Not known |
| CVE-2023-2868 | Barracuda Networks | Barracuda Networks ESG Appliance Improper Input Validation Vulnerability | Severity: Critical CVSS 9.8 | May 26, 2023 | Not known |
| CVE-2023-32373 | Apple | Apple Multiple Products WebKit Use-After-Free Vulnerability | Severity: High CVSS 8.8 | May 22, 2023 | Not known |
| CVE-2023-32409 | Apple | Apple Multiple Products WebKit Sandbox Escape Vulnerability | Severity: High CVSS 8.6 | May 22, 2023 | Not known |
| CVE-2023-28204 | Apple | Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability | Severity: Elevated CVSS 6.5 | May 22, 2023 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
