Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2025-68686 | Fortinet | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | Severity: Elevated CVSS 5.9 | Jul 27, 2026 | Not known |
| CVE-2026-50522 | Microsoft | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Jul 22, 2026 | Not known |
| CVE-2026-16232 | Check Point | Check Point SmartConsole Improper Authentication Vulnerability | Severity: Critical CVSS 9.3 | Jul 22, 2026 | Not known |
| CVE-2026-0770 | Langflow | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | Severity: Critical CVSS 9.8 | Jul 21, 2026 | Not known |
| CVE-2026-63030 | WordPress | WordPress Core Interpretation Conflict Vulnerability | Severity: Critical CVSS 9.8 | Jul 21, 2026 | Not known |
| CVE-2021-27137 | DD-WRT | DD-WRT Stack-Based Buffer Overflow Vulnerability | Severity: High CVSS 8.1 | Jul 21, 2026 | Not known |
| CVE-2026-60137 | WordPress | WordPress Core SQL Injection Vulnerability | Severity: Elevated CVSS 5.9 | Jul 21, 2026 | Not known |
| CVE-2026-25089 | Fortinet | Fortinet FortiSandbox OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Jul 16, 2026 | Not known |
| CVE-2026-39808 | Fortinet | Fortinet FortiSandbox OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Jul 16, 2026 | Not known |
| CVE-2026-58644 | Microsoft | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Jul 16, 2026 | Not known |
| CVE-2026-46817 | Oracle | Oracle E-Business Suite Improper Privilege Management Vulnerability | Severity: Critical CVSS 9.8 | Jul 15, 2026 | Not known |
| CVE-2023-4346 | KNX Association | KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | Severity: High CVSS 7.5 | Jul 15, 2026 | Not known |
| CVE-2026-15409 | SonicWall | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | Severity: Critical CVSS 10.0 | Jul 14, 2026 | Known |
| CVE-2026-56164 | Microsoft | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | Severity: Critical CVSS 9.8 | Jul 14, 2026 | Not known |
| CVE-2026-56155 | Microsoft | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | Severity: High CVSS 7.8 | Jul 14, 2026 | Not known |
| CVE-2026-15410 | SonicWall | SonicWall SMA1000 Appliances Code Injection Vulnerability | Severity: High CVSS 7.2 | Jul 14, 2026 | Known |
| CVE-2008-4128 | Cisco | Cisco IOS Cross-Site Request Forgery Vulnerability | Severity: High CVSS 8.1 | Jul 13, 2026 | Not known |
| CVE-2026-48939 | iCagenda | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | Severity: Critical CVSS 10.0 | Jul 10, 2026 | Not known |
| CVE-2026-56291 | Balbooa | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | Severity: Critical CVSS 10.0 | Jul 10, 2026 | Not known |
| CVE-2026-48282 | Adobe | Adobe ColdFusion Path Traversal Vulnerability | Severity: Critical CVSS 10.0 | Jul 7, 2026 | Not known |
| CVE-2026-48908 | JoomShaper | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | Severity: Critical CVSS 10.0 | Jul 7, 2026 | Not known |
| CVE-2026-56290 | Joomlack | Joomlack Page Builder Improper Access Control Vulnerability | Severity: Critical CVSS 10.0 | Jul 7, 2026 | Not known |
| CVE-2026-55255 | Langflow | Langflow Authorization Bypass Through User-Controlled Key Vulnerability | Severity: High CVSS 8.4 | Jul 7, 2026 | Not known |
| CVE-2026-45659 | Microsoft | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | Severity: High CVSS 8.8 | Jul 1, 2026 | Known |
| CVE-2026-48558 | SimpleHelp | SimpleHelp Authentication Bypass Vulnerability | Severity: Critical CVSS 9.5 | Jun 29, 2026 | Not known |
| CVE-2026-12569 | PTC | PTC Windchill and FlexPLM Improper Input Validation Vulnerability | Severity: Critical CVSS 9.3 | Jun 25, 2026 | Known |
| CVE-2026-20230 | Cisco | Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability | Severity: High CVSS 8.6 | Jun 25, 2026 | Not known |
| CVE-2026-34908 | Ubiquiti | Ubiquiti UniFi OS Improper Access Control Vulnerability | Severity: Critical CVSS 10.0 | Jun 23, 2026 | Not known |
| CVE-2026-34909 | Ubiquiti | Ubiquiti UniFi OS Path Traversal Vulnerability | Severity: Critical CVSS 10.0 | Jun 23, 2026 | Not known |
| CVE-2026-34910 | Ubiquiti | Ubiquiti UniFi OS Improper Input Validation Vulnerability | Severity: Critical CVSS 10.0 | Jun 23, 2026 | Not known |
| CVE-2025-67038 | Lantronix | Lantronix EDS5000 Code Injection Vulnerability | Severity: Critical CVSS 9.3 | Jun 23, 2026 | Not known |
| CVE-2026-20253 | Splunk | Splunk Enterprise Missing Authentication for Critical Function Vulnerability | Severity: Critical CVSS 9.8 | Jun 18, 2026 | Not known |
| CVE-2026-48907 | Widget Factory | Widget Factory Joomla Content Editor Improper Access Control Vulnerability | Severity: Critical CVSS 10.0 | Jun 16, 2026 | Not known |
| CVE-2026-54420 | LiteSpeed | LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability | Severity: High CVSS 8.5 | Jun 15, 2026 | Not known |
| CVE-2026-20262 | Cisco | Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability | Severity: Elevated CVSS 6.5 | Jun 15, 2026 | Not known |
| CVE-2026-35273 | Oracle | Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability | Severity: Critical CVSS 9.8 | Jun 12, 2026 | Known |
| CVE-2026-10520 | Ivanti | Ivanti Sentry OS Command Injection Vulnerability | Severity: Critical CVSS 10.0 | Jun 11, 2026 | Not known |
| CVE-2026-11645 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | Severity: High CVSS 8.8 | Jun 9, 2026 | Not known | |
| CVE-2026-20245 | Cisco | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability | Severity: High CVSS 7.8 | Jun 9, 2026 | Not known |
| CVE-2026-7473 | Arista | Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability | Severity: Elevated CVSS 6.9 | Jun 9, 2026 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
