Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2011-4723 | D-Link | D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability | Severity: Elevated CVSS 5.7 | Sep 8, 2022 | Not known |
| CVE-2020-9934 | Apple | Apple iOS, iPadOS, and macOS Input Validation Vulnerability | Severity: Elevated CVSS 5.5 | Sep 8, 2022 | Not known |
| CVE-2018-13374 | Fortinet | Fortinet FortiOS and FortiADC Improper Access Control Vulnerability | Severity: Elevated CVSS 4.3 | Sep 8, 2022 | Known |
| CVE-2022-22963 | VMware Tanzu | VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Aug 25, 2022 | Not known |
| CVE-2022-24112 | Apache | Apache APISIX Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Aug 25, 2022 | Not known |
| CVE-2022-24706 | Apache | Apache CouchDB Insecure Default Initialization of Resource Vulnerability | Severity: Critical CVSS 9.8 | Aug 25, 2022 | Not known |
| CVE-2022-26352 | dotCMS | dotCMS Unrestricted Upload of File Vulnerability | Severity: Critical CVSS 9.8 | Aug 25, 2022 | Known |
| CVE-2022-2294 | WebRTC | WebRTC Heap Buffer Overflow Vulnerability | Severity: High CVSS 8.8 | Aug 25, 2022 | Known |
| CVE-2020-28949 | PEAR | PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability | Severity: High CVSS 7.8 | Aug 25, 2022 | Not known |
| CVE-2021-38406 | Delta Electronics | Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability | Severity: High CVSS 7.8 | Aug 25, 2022 | Not known |
| CVE-2020-36193 | PEAR | PEAR Archive_Tar Improper Link Resolution Vulnerability | Severity: High CVSS 7.5 | Aug 25, 2022 | Not known |
| CVE-2021-31010 | Apple | Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability | Severity: High CVSS 7.5 | Aug 25, 2022 | Not known |
| CVE-2021-39226 | Grafana Labs | Grafana Authentication Bypass Vulnerability | Severity: High CVSS 7.3 | Aug 25, 2022 | Not known |
| CVE-2022-0028 | Palo Alto Networks | Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability | Severity: High CVSS 8.6 | Aug 22, 2022 | Not known |
| CVE-2022-22536 | SAP | SAP Multiple Products HTTP Request Smuggling Vulnerability | Severity: Critical CVSS 10.0 | Aug 18, 2022 | Not known |
| CVE-2017-15944 | Palo Alto Networks | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Aug 18, 2022 | Not known |
| CVE-2022-26923 | Microsoft | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | Aug 18, 2022 | Not known |
| CVE-2022-32893 | Apple | Apple iOS and macOS Out-of-Bounds Write Vulnerability | Severity: High CVSS 8.8 | Aug 18, 2022 | Not known |
| CVE-2022-21971 | Microsoft | Microsoft Windows Runtime Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Aug 18, 2022 | Not known |
| CVE-2022-32894 | Apple | Apple iOS and macOS Out-of-Bounds Write Vulnerability | Severity: High CVSS 7.8 | Aug 18, 2022 | Not known |
| CVE-2022-2856 | Google Chromium Intents Insufficient Input Validation Vulnerability | Severity: Elevated CVSS 6.5 | Aug 18, 2022 | Not known | |
| CVE-2022-37042 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Aug 11, 2022 | Known |
| CVE-2022-27925 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability | Severity: High CVSS 7.2 | Aug 11, 2022 | Known |
| CVE-2022-34713 | Microsoft | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Aug 9, 2022 | Not known |
| CVE-2022-30333 | RARLAB | RARLAB UnRAR Directory Traversal Vulnerability | Severity: High CVSS 7.5 | Aug 9, 2022 | Known |
| CVE-2022-27924 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability | Severity: High CVSS 7.5 | Aug 4, 2022 | Known |
| CVE-2022-26138 | Atlassian | Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability | Severity: Critical CVSS 9.8 | Jul 29, 2022 | Not known |
| CVE-2022-22047 | Microsoft | Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jul 12, 2022 | Not known |
| CVE-2022-26925 | Microsoft | Microsoft Windows LSA Spoofing Vulnerability | Severity: Elevated CVSS 5.9 | Jul 1, 2022 | Not known |
| CVE-2022-29499 | Mitel | Mitel MiVoice Connect Data Validation Vulnerability | Severity: Critical CVSS 9.8 | Jun 27, 2022 | Known |
| CVE-2018-4344 | Apple | Apple Multiple Products Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Jun 27, 2022 | Not known |
| CVE-2019-8605 | Apple | Apple Multiple Products Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Jun 27, 2022 | Not known |
| CVE-2020-3837 | Apple | Apple Multiple Products Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Jun 27, 2022 | Not known |
| CVE-2020-9907 | Apple | Apple Multiple Products Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Jun 27, 2022 | Not known |
| CVE-2021-30983 | Apple | Apple iOS and iPadOS Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Jun 27, 2022 | Not known |
| CVE-2021-4034 | Red Hat | Red Hat Polkit Out-of-Bounds Read and Write Vulnerability | Severity: High CVSS 7.8 | Jun 27, 2022 | Known |
| CVE-2021-30533 | Google Chromium PopupBlocker Security Bypass Vulnerability | Severity: Elevated CVSS 6.5 | Jun 27, 2022 | Not known | |
| CVE-2022-30190 | Microsoft | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Jun 14, 2022 | Known |
| CVE-2016-2386 | SAP | SAP NetWeaver SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Jun 9, 2022 | Not known |
| CVE-2021-38163 | SAP | SAP NetWeaver Unrestricted File Upload Vulnerability | Severity: High CVSS 8.8 | Jun 9, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
