Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2016-2388 | SAP | SAP NetWeaver Information Disclosure Vulnerability | Severity: Elevated CVSS 5.3 | Jun 9, 2022 | Not known |
| CVE-2011-2462 | Adobe | Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability | Severity: Critical CVSS 9.8 | Jun 8, 2022 | Not known |
| CVE-2017-6862 | NETGEAR | NETGEAR Multiple Devices Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Jun 8, 2022 | Not known |
| CVE-2019-7192 | QNAP | QNAP Photo Station Improper Access Control Vulnerability | Severity: Critical CVSS 9.8 | Jun 8, 2022 | Known |
| CVE-2019-7193 | QNAP | QNAP QTS Improper Input Validation Vulnerability | Severity: Critical CVSS 9.8 | Jun 8, 2022 | Known |
| CVE-2019-7194 | QNAP | QNAP Photo Station Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Jun 8, 2022 | Known |
| CVE-2019-7195 | QNAP | QNAP Photo Station Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Jun 8, 2022 | Known |
| CVE-2006-2492 | Microsoft | Microsoft Word Malformed Object Pointer Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known |
| CVE-2008-0655 | Adobe | Adobe Acrobat and Reader Unspecified Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known |
| CVE-2009-3953 | Adobe | Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known |
| CVE-2012-1889 | Microsoft | Microsoft XML Core Services Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known |
| CVE-2012-5054 | Adobe | Adobe Flash Player Integer Overflow Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known |
| CVE-2016-1646 | Google Chromium V8 Out-of-Bounds Read Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known | |
| CVE-2016-5198 | Google Chromium V8 Out-of-Bounds Memory Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known | |
| CVE-2017-5030 | Google Chromium V8 Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known | |
| CVE-2017-5070 | Google Chromium V8 Type Confusion Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known | |
| CVE-2018-17463 | Google Chromium V8 Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known | |
| CVE-2018-17480 | Google Chromium V8 Out-of-Bounds Write Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known | |
| CVE-2018-4990 | Adobe | Adobe Acrobat and Reader Double Free Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known |
| CVE-2018-6065 | Google Chromium V8 Integer Overflow Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known | |
| CVE-2019-15271 | Cisco | Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known |
| CVE-2012-0754 | Adobe | Adobe Flash Player Memory Corruption Vulnerability | Severity: High CVSS 8.1 | Jun 8, 2022 | Not known |
| CVE-2012-4969 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.1 | Jun 8, 2022 | Not known |
| CVE-2007-5659 | Adobe | Adobe Acrobat and Reader Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2009-0557 | Microsoft | Microsoft Office Object Record Corruption Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2009-0563 | Microsoft | Microsoft Office Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2009-1862 | Adobe | Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2009-4324 | Adobe | Adobe Acrobat and Reader Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2010-1297 | Adobe | Adobe Flash Player Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2010-2572 | Microsoft | Microsoft PowerPoint Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2011-0609 | Adobe | Adobe Flash Player Unspecified Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2012-0151 | Microsoft | Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2013-1331 | Microsoft | Microsoft Office Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2010-2883 | Adobe | Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.3 | Jun 8, 2022 | Not known |
| CVE-2019-5825 | Google Chromium V8 Out-of-Bounds Write Vulnerability | Severity: Elevated CVSS 6.5 | Jun 8, 2022 | Not known | |
| CVE-2012-0767 | Adobe | Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Jun 8, 2022 | Not known |
| CVE-2022-26134 | Atlassian | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Jun 2, 2022 | Known |
| CVE-2010-0840 | Oracle | Oracle JRE Unspecified Vulnerability | Severity: Critical CVSS 9.8 | May 25, 2022 | Not known |
| CVE-2012-1710 | Oracle | Oracle Fusion Middleware Unspecified Vulnerability | Severity: Critical CVSS 9.8 | May 25, 2022 | Known |
| CVE-2013-0422 | Oracle | Oracle JRE Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | May 25, 2022 | Known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
