Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2022-41128 | Microsoft | Microsoft Windows Scripting Languages Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Nov 8, 2022 | Not known |
| CVE-2022-41073 | Microsoft | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 8, 2022 | Known |
| CVE-2022-41125 | Microsoft | Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 8, 2022 | Not known |
| CVE-2021-25337 | Samsung | Samsung Mobile Devices Improper Access Control Vulnerability | Severity: High CVSS 7.1 | Nov 8, 2022 | Not known |
| CVE-2021-25369 | Samsung | Samsung Mobile Devices Improper Access Control Vulnerability | Severity: Elevated CVSS 5.5 | Nov 8, 2022 | Not known |
| CVE-2022-41091 | Microsoft | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability | Severity: Elevated CVSS 5.4 | Nov 8, 2022 | Known |
| CVE-2021-25370 | Samsung | Samsung Mobile Devices Memory Corruption Vulnerability | Severity: Elevated CVSS 4.4 | Nov 8, 2022 | Not known |
| CVE-2022-3723 | Google Chromium V8 Type Confusion Vulnerability | Severity: High CVSS 8.8 | Oct 28, 2022 | Not known | |
| CVE-2022-42827 | Apple | Apple iOS and iPadOS Out-of-Bounds Write Vulnerability | Severity: High CVSS 7.8 | Oct 25, 2022 | Not known |
| CVE-2018-19323 | GIGABYTE | GIGABYTE Multiple Products Privilege Escalation Vulnerability | Severity: Critical CVSS 9.8 | Oct 24, 2022 | Known |
| CVE-2018-19320 | GIGABYTE | GIGABYTE Multiple Products Unspecified Vulnerability | Severity: High CVSS 7.8 | Oct 24, 2022 | Known |
| CVE-2018-19321 | GIGABYTE | GIGABYTE Multiple Products Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Oct 24, 2022 | Known |
| CVE-2018-19322 | GIGABYTE | GIGABYTE Multiple Products Code Execution Vulnerability | Severity: High CVSS 7.8 | Oct 24, 2022 | Known |
| CVE-2020-3433 | Cisco | Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability | Severity: High CVSS 7.8 | Oct 24, 2022 | Known |
| CVE-2020-3153 | Cisco | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability | Severity: Elevated CVSS 6.5 | Oct 24, 2022 | Known |
| CVE-2022-41352 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability | Severity: Critical CVSS 9.8 | Oct 20, 2022 | Known |
| CVE-2021-3493 | Linux | Linux Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Oct 20, 2022 | Not known |
| CVE-2022-40684 | Fortinet | Fortinet Multiple Products Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Oct 11, 2022 | Known |
| CVE-2022-41033 | Microsoft | Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Oct 11, 2022 | Not known |
| CVE-2022-36804 | Atlassian | Atlassian Bitbucket Server and Data Center Command Injection Vulnerability | Severity: High CVSS 8.8 | Sep 30, 2022 | Not known |
| CVE-2022-41040 | Microsoft | Microsoft Exchange Server Server-Side Request Forgery Vulnerability | Severity: High CVSS 8.8 | Sep 30, 2022 | Known |
| CVE-2022-41082 | Microsoft | Microsoft Exchange Server Remote Code Execution Vulnerability | Severity: High CVSS 8.0 | Sep 30, 2022 | Known |
| CVE-2022-3236 | Sophos | Sophos Firewall Code Injection Vulnerability | Severity: Critical CVSS 9.8 | Sep 23, 2022 | Not known |
| CVE-2022-35405 | Zoho | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Sep 22, 2022 | Not known |
| CVE-2013-6282 | Linux | Linux Kernel Improper Input Validation Vulnerability | Severity: High CVSS 8.8 | Sep 15, 2022 | Not known |
| CVE-2013-2094 | Linux | Linux Kernel Privilege Escalation Vulnerability | Severity: High CVSS 8.4 | Sep 15, 2022 | Not known |
| CVE-2013-2597 | Code Aurora | Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability | Severity: High CVSS 8.4 | Sep 15, 2022 | Not known |
| CVE-2010-2568 | Microsoft | Microsoft Windows Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Sep 15, 2022 | Not known |
| CVE-2013-2596 | Linux | Linux Kernel Integer Overflow Vulnerability | Severity: High CVSS 7.8 | Sep 15, 2022 | Not known |
| CVE-2022-40139 | Trend Micro | Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability | Severity: High CVSS 7.2 | Sep 15, 2022 | Not known |
| CVE-2022-32917 | Apple | Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Sep 14, 2022 | Not known |
| CVE-2022-37969 | Microsoft | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Sep 14, 2022 | Known |
| CVE-2018-2628 | Oracle | Oracle WebLogic Server Unspecified Vulnerability | Severity: Critical CVSS 9.8 | Sep 8, 2022 | Not known |
| CVE-2018-6530 | D-Link | D-Link Multiple Routers OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Sep 8, 2022 | Known |
| CVE-2018-7445 | MikroTik | MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Sep 8, 2022 | Not known |
| CVE-2022-26258 | D-Link | D-Link DIR-820L Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Sep 8, 2022 | Not known |
| CVE-2022-3075 | Google Chromium Mojo Insufficient Data Validation Vulnerability | Severity: Critical CVSS 9.6 | Sep 8, 2022 | Not known | |
| CVE-2022-27593 | QNAP | QNAP Photo Station Externally Controlled Reference Vulnerability | Severity: Critical CVSS 9.1 | Sep 8, 2022 | Known |
| CVE-2017-5521 | NETGEAR | NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability | Severity: High CVSS 8.1 | Sep 8, 2022 | Not known |
| CVE-2011-1823 | Android | Android OS Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Sep 8, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
