Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2014-0546 | Adobe | Adobe Reader and Acrobat Sandbox Bypass Vulnerability | Severity: Critical CVSS 9.8 | May 25, 2022 | Not known |
| CVE-2014-2817 | Microsoft | Microsoft Internet Explorer Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2014-4123 | Microsoft | Microsoft Internet Explorer Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2014-4148 | Microsoft | Microsoft Windows Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2014-8439 | Adobe | Adobe Flash Player Dereferenced Pointer Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2015-2360 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2015-2425 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2015-4495 | Mozilla | Mozilla Firefox Security Feature Bypass Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2015-8651 | Adobe | Adobe Flash Player Integer Overflow Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2016-0034 | Microsoft | Microsoft Silverlight Runtime Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Known |
| CVE-2016-0984 | Adobe | Adobe Flash Player and AIR Use-After-Free Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2016-1010 | Adobe | Adobe Flash Player and AIR Integer Overflow Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2016-7256 | Microsoft | Microsoft Windows Open Type Font Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2019-3010 | Oracle | Oracle Solaris Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2013-0074 | Microsoft | Microsoft Silverlight Double Dereference Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Known |
| CVE-2014-3153 | Linux | Linux Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2014-4077 | Microsoft | Microsoft IME Japanese Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2015-0016 | Microsoft | Microsoft Windows TS WebProxy Directory Traversal Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2015-0310 | Adobe | Adobe Flash Player ASLR Bypass Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2015-1671 | Microsoft | Microsoft Windows Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2015-6175 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2016-3393 | Microsoft | Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2010-1428 | Red Hat | Red Hat JBoss Information Disclosure Vulnerability | Severity: High CVSS 7.5 | May 25, 2022 | Known |
| CVE-2015-1769 | Microsoft | Microsoft Windows Mount Manager Privilege Escalation Vulnerability | Severity: Elevated CVSS 6.6 | May 25, 2022 | Not known |
| CVE-2013-3993 | IBM | IBM InfoSphere BigInsights Invalid Input Vulnerability | Severity: Elevated CVSS 6.5 | May 25, 2022 | Known |
| CVE-2013-7331 | Microsoft | Microsoft Internet Explorer Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 25, 2022 | Not known |
| CVE-2015-0071 | Microsoft | Microsoft Internet Explorer ASLR Bypass Vulnerability | Severity: Elevated CVSS 6.5 | May 25, 2022 | Not known |
| CVE-2013-3896 | Microsoft | Microsoft Silverlight Information Disclosure Vulnerability | Severity: Elevated CVSS 5.5 | May 25, 2022 | Not known |
| CVE-2010-0738 | Red Hat | Red Hat JBoss Authentication Bypass Vulnerability | Severity: Elevated CVSS 5.3 | May 25, 2022 | Known |
| CVE-2013-0431 | Oracle | Oracle JRE Sandbox Bypass Vulnerability | Severity: Elevated CVSS 5.3 | May 25, 2022 | Known |
| CVE-2013-2423 | Oracle | Oracle JRE Unspecified Vulnerability | Severity: Informational CVSS 3.7 | May 25, 2022 | Not known |
| CVE-2017-18362 | Kaseya | Kaseya VSA SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | May 24, 2022 | Known |
| CVE-2017-8543 | Microsoft | Microsoft Windows Search Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | May 24, 2022 | Not known |
| CVE-2018-19949 | QNAP | QNAP NAS File Station Command Injection Vulnerability | Severity: Critical CVSS 9.8 | May 24, 2022 | Known |
| CVE-2016-4657 | Apple | Apple iOS Webkit Memory Corruption Vulnerability | Severity: High CVSS 8.8 | May 24, 2022 | Not known |
| CVE-2016-6366 | Cisco | Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability | Severity: High CVSS 8.8 | May 24, 2022 | Not known |
| CVE-2017-0149 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: High CVSS 8.8 | May 24, 2022 | Not known |
| CVE-2017-0210 | Microsoft | Microsoft Internet Explorer Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | May 24, 2022 | Not known |
| CVE-2016-4656 | Apple | Apple iOS Memory Corruption Vulnerability | Severity: High CVSS 7.8 | May 24, 2022 | Not known |
| CVE-2016-6367 | Cisco | Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | May 24, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
