Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2019-1003029 | Jenkins | Jenkins Script Security Plugin Sandbox Bypass Vulnerability | Severity: Critical CVSS 9.9 | Apr 25, 2022 | Not known |
| CVE-2022-29464 | WSO2 | WSO2 Multiple Products Unrestrictive Upload of File Vulnerability | Severity: Critical CVSS 9.8 | Apr 25, 2022 | Known |
| CVE-2021-40450 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 25, 2022 | Not known |
| CVE-2021-41357 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 25, 2022 | Not known |
| CVE-2022-0847 | Linux | Linux Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 25, 2022 | Not known |
| CVE-2022-21919 | Microsoft | Microsoft Windows User Profile Service Privilege Escalation Vulnerability | Severity: High CVSS 7.0 | Apr 25, 2022 | Not known |
| CVE-2022-26904 | Microsoft | Microsoft Windows User Profile Service Privilege Escalation Vulnerability | Severity: High CVSS 7.0 | Apr 25, 2022 | Not known |
| CVE-2019-3568 | Meta Platforms | WhatsApp VOIP Stack Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Apr 19, 2022 | Not known |
| CVE-2022-22718 | Microsoft | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 19, 2022 | Not known |
| CVE-2018-6882 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Apr 19, 2022 | Known |
| CVE-2007-3010 | Alcatel | Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Apr 15, 2022 | Not known |
| CVE-2010-5330 | Ubiquiti | Ubiquiti AirOS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Apr 15, 2022 | Not known |
| CVE-2014-0780 | InduSoft | InduSoft Web Studio NTWebServer Directory Traversal Vulnerability | Severity: Critical CVSS 9.8 | Apr 15, 2022 | Not known |
| CVE-2018-7841 | Schneider Electric | Schneider Electric U.motion Builder SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Apr 15, 2022 | Not known |
| CVE-2019-16057 | D-Link | D-Link DNS-320 Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Apr 15, 2022 | Known |
| CVE-2019-3929 | Crestron | Crestron Multiple Products Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Apr 15, 2022 | Not known |
| CVE-2022-1364 | Google Chromium V8 Type Confusion Vulnerability | Severity: High CVSS 8.8 | Apr 15, 2022 | Not known | |
| CVE-2022-22960 | VMware | VMware Multiple Products Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 15, 2022 | Not known |
| CVE-2016-4523 | Trihedral | Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability | Severity: High CVSS 7.5 | Apr 15, 2022 | Not known |
| CVE-2022-22954 | VMware | VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability | Severity: Critical CVSS 9.8 | Apr 14, 2022 | Known |
| CVE-2015-0311 | Adobe | Adobe Flash Player Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Apr 13, 2022 | Not known |
| CVE-2015-0313 | Adobe | Adobe Flash Player Use-After-Free Vulnerability | Severity: Critical CVSS 9.8 | Apr 13, 2022 | Not known |
| CVE-2015-3113 | Adobe | Adobe Flash Player Heap-Based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Apr 13, 2022 | Not known |
| CVE-2015-5122 | Adobe | Adobe Flash Player Use-After-Free Vulnerability | Severity: Critical CVSS 9.8 | Apr 13, 2022 | Not known |
| CVE-2015-5123 | Adobe | Adobe Flash Player Use-After-Free Vulnerability | Severity: Critical CVSS 9.8 | Apr 13, 2022 | Not known |
| CVE-2018-20753 | Kaseya | Kaseya VSA Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Apr 13, 2022 | Known |
| CVE-2018-7602 | Drupal | Drupal Core Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Apr 13, 2022 | Known |
| CVE-2015-2502 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Apr 13, 2022 | Not known |
| CVE-2014-9163 | Adobe | Adobe Flash Player Stack-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Apr 13, 2022 | Not known |
| CVE-2022-24521 | Microsoft | Microsoft Windows CLFS Driver Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 13, 2022 | Known |
| CVE-2017-11317 | Telerik | Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability | Severity: Critical CVSS 9.8 | Apr 11, 2022 | Not known |
| CVE-2020-2509 | QNAP | QNAP Network-Attached Storage (NAS) Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Apr 11, 2022 | Not known |
| CVE-2021-27852 | Checkbox | Checkbox Survey Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Apr 11, 2022 | Not known |
| CVE-2022-23176 | WatchGuard | WatchGuard Firebox and XTM Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | Apr 11, 2022 | Not known |
| CVE-2021-39793 | Google Pixel Out-of-Bounds Write Vulnerability | Severity: High CVSS 7.8 | Apr 11, 2022 | Not known | |
| CVE-2021-42278 | Microsoft | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | Severity: High CVSS 7.5 | Apr 11, 2022 | Known |
| CVE-2021-42287 | Microsoft | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | Severity: High CVSS 7.5 | Apr 11, 2022 | Known |
| CVE-2021-22600 | Linux | Linux Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.0 | Apr 11, 2022 | Not known |
| CVE-2021-31166 | Microsoft | Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Apr 6, 2022 | Not known |
| CVE-2017-0148 | Microsoft | Microsoft SMBv1 Server Remote Code Execution Vulnerability | Severity: High CVSS 8.1 | Apr 6, 2022 | Known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
