Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2021-3156 | Sudo | Sudo Heap-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Apr 6, 2022 | Not known |
| CVE-2021-45382 | D-Link | D-Link Multiple Routers Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Apr 4, 2022 | Not known |
| CVE-2022-22965 | VMware | Spring Framework JDK 9+ Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Apr 4, 2022 | Not known |
| CVE-2022-22675 | Apple | Apple macOS Out-of-Bounds Write Vulnerability | Severity: High CVSS 7.8 | Apr 4, 2022 | Not known |
| CVE-2022-22674 | Apple | Apple macOS Out-of-Bounds Read Vulnerability | Severity: Elevated CVSS 5.5 | Apr 4, 2022 | Not known |
| CVE-2018-10561 | Dasan | Dasan GPON Routers Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Mar 31, 2022 | Not known |
| CVE-2018-10562 | Dasan | Dasan GPON Routers Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Mar 31, 2022 | Known |
| CVE-2021-28799 | QNAP | QNAP NAS Improper Authorization Vulnerability | Severity: Critical CVSS 9.8 | Mar 31, 2022 | Known |
| CVE-2022-1040 | Sophos | Sophos Firewall Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Mar 31, 2022 | Not known |
| CVE-2022-26871 | Trend Micro | Trend Micro Apex Central Arbitrary File Upload Vulnerability | Severity: Critical CVSS 9.8 | Mar 31, 2022 | Not known |
| CVE-2021-21551 | Dell | Dell dbutil Driver Insufficient Access Control Vulnerability | Severity: High CVSS 7.8 | Mar 31, 2022 | Not known |
| CVE-2021-34484 | Microsoft | Microsoft Windows User Profile Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 31, 2022 | Not known |
| CVE-2022-0543 | Redis | Debian-specific Redis Server Lua Sandbox Escape Vulnerability | Severity: Critical CVSS 10.0 | Mar 28, 2022 | Not known |
| CVE-2012-5076 | Oracle | Oracle Java SE Sandbox Bypass Vulnerability | Severity: Critical CVSS 9.8 | Mar 28, 2022 | Not known |
| CVE-2013-2465 | Oracle | Oracle Java SE Unspecified Vulnerability | Severity: Critical CVSS 9.8 | Mar 28, 2022 | Known |
| CVE-2013-2729 | Adobe | Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Mar 28, 2022 | Not known |
| CVE-2021-20028 | SonicWall | SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Mar 28, 2022 | Known |
| CVE-2013-1690 | Mozilla | Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known |
| CVE-2013-2551 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Known |
| CVE-2015-1770 | Microsoft | Microsoft Office Uninitialized Memory Use Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known |
| CVE-2015-2419 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known |
| CVE-2015-2426 | Microsoft | Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known |
| CVE-2016-7200 | Microsoft | Microsoft Edge Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known |
| CVE-2016-7201 | Microsoft | Microsoft Edge Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known |
| CVE-2022-1096 | Google Chromium V8 Type Confusion Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known | |
| CVE-2017-0037 | Microsoft | Microsoft Edge and Internet Explorer Type Confusion Vulnerability | Severity: High CVSS 8.1 | Mar 28, 2022 | Not known |
| CVE-2010-4398 | Microsoft | Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2011-2005 | Microsoft | Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2012-2539 | Microsoft | Microsoft Word Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2013-3660 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2016-0040 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2016-0151 | Microsoft | Microsoft Windows CSRSS Security Feature Bypass Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Known |
| CVE-2018-8405 | Microsoft | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Known |
| CVE-2018-8406 | Microsoft | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Known |
| CVE-2018-8440 | Microsoft | Microsoft Windows Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Known |
| CVE-2021-34486 | Microsoft | Microsoft Windows Event Tracing Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2021-38646 | Microsoft | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Known |
| CVE-2012-2034 | Adobe | Adobe Flash Player Memory Corruption Vulnerability | Severity: High CVSS 7.5 | Mar 28, 2022 | Not known |
| CVE-2016-0189 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: High CVSS 7.5 | Mar 28, 2022 | Known |
| CVE-2019-7483 | SonicWall | SonicWall SMA100 Directory Traversal Vulnerability | Severity: High CVSS 7.5 | Mar 28, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
