Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2017-0005 | Microsoft | Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 24, 2022 | Not known |
| CVE-2017-8291 | Artifex | Artifex Ghostscript Type Confusion Vulnerability | Severity: High CVSS 7.8 | May 24, 2022 | Not known |
| CVE-2018-8611 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 24, 2022 | Not known |
| CVE-2017-0147 | Microsoft | Microsoft Windows SMBv1 Information Disclosure Vulnerability | Severity: High CVSS 7.5 | May 24, 2022 | Known |
| CVE-2016-3298 | Microsoft | Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 24, 2022 | Not known |
| CVE-2016-3351 | Microsoft | Microsoft Internet Explorer and Edge Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 24, 2022 | Known |
| CVE-2017-0022 | Microsoft | Microsoft XML Core Services Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 24, 2022 | Not known |
| CVE-2018-19953 | QNAP | QNAP NAS File Station Cross-Site Scripting Vulnerability | Severity: Elevated CVSS 6.1 | May 24, 2022 | Known |
| CVE-2016-4655 | Apple | Apple iOS Information Disclosure Vulnerability | Severity: Elevated CVSS 5.5 | May 24, 2022 | Not known |
| CVE-2018-19943 | QNAP | QNAP NAS File Station Cross-Site Scripting Vulnerability | Severity: Elevated CVSS 5.4 | May 24, 2022 | Known |
| CVE-2016-0162 | Microsoft | Microsoft Internet Explorer Information Disclosure Vulnerability | Severity: Elevated CVSS 4.3 | May 24, 2022 | Not known |
| CVE-2019-11708 | Mozilla | Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability | Severity: Critical CVSS 10.0 | May 23, 2022 | Not known |
| CVE-2019-11707 | Mozilla | Mozilla Firefox and Thunderbird Type Confusion Vulnerability | Severity: High CVSS 8.8 | May 23, 2022 | Not known |
| CVE-2019-13720 | Google Chrome WebAudio Use-After-Free Vulnerability | Severity: High CVSS 8.8 | May 23, 2022 | Not known | |
| CVE-2019-8720 | WebKitGTK | WebKitGTK Memory Corruption Vulnerability | Severity: High CVSS 8.8 | May 23, 2022 | Not known |
| CVE-2019-18426 | Meta Platforms | WhatsApp Cross-Site Scripting Vulnerability | Severity: High CVSS 8.2 | May 23, 2022 | Not known |
| CVE-2018-5002 | Adobe | Adobe Flash Player Stack-based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Not known |
| CVE-2018-8589 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Not known |
| CVE-2019-0880 | Microsoft | Microsoft Windows Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Not known |
| CVE-2019-1130 | Microsoft | Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Known |
| CVE-2019-1385 | Microsoft | Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Known |
| CVE-2019-7286 | Apple | Apple Multiple Products Memory Corruption Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Not known |
| CVE-2019-7287 | Apple | Apple iOS Memory Corruption Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Not known |
| CVE-2020-0638 | Microsoft | Microsoft Update Notification Manager Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Known |
| CVE-2020-1027 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Not known |
| CVE-2021-1048 | Android | Android Kernel Use-After-Free Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Not known |
| CVE-2021-30883 | Apple | Apple Multiple Products Memory Corruption Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Not known |
| CVE-2019-0676 | Microsoft | Microsoft Internet Explorer Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 23, 2022 | Not known |
| CVE-2019-0703 | Microsoft | Microsoft Windows SMB Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 23, 2022 | Not known |
| CVE-2019-5786 | Google Chrome Blink Use-After-Free Vulnerability | Severity: Elevated CVSS 6.5 | May 23, 2022 | Not known | |
| CVE-2022-20821 | Cisco | Cisco IOS XR Open Port Vulnerability | Severity: Elevated CVSS 6.5 | May 23, 2022 | Not known |
| CVE-2021-0920 | Android | Android Kernel Race Condition Vulnerability | Severity: Elevated CVSS 6.4 | May 23, 2022 | Not known |
| CVE-2022-22947 | VMware | VMware Spring Cloud Gateway Code Injection Vulnerability | Severity: Critical CVSS 10.0 | May 16, 2022 | Not known |
| CVE-2022-30525 | Zyxel | Zyxel Multiple Firewalls OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | May 16, 2022 | Not known |
| CVE-2022-1388 | F5 | F5 BIG-IP Missing Authentication Vulnerability | Severity: Critical CVSS 9.8 | May 10, 2022 | Known |
| CVE-2014-0322 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.8 | May 4, 2022 | Not known |
| CVE-2019-8506 | Apple | Apple Multiple Products Type Confusion Vulnerability | Severity: High CVSS 8.8 | May 4, 2022 | Not known |
| CVE-2021-1789 | Apple | Apple Multiple Products Type Confusion Vulnerability | Severity: High CVSS 8.8 | May 4, 2022 | Not known |
| CVE-2014-4113 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 4, 2022 | Not known |
| CVE-2014-0160 | OpenSSL | OpenSSL Information Disclosure Vulnerability | Severity: High CVSS 7.5 | May 4, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
