Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2015-4068 | Arcserve | Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability | Severity: Critical CVSS 9.1 | Mar 25, 2022 | Not known |
| CVE-2009-0927 | Adobe | Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2014-6324 | Microsoft | Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2014-6332 | Microsoft | Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2016-7892 | Adobe | Adobe Flash Player Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2017-0146 | Microsoft | Microsoft Windows SMB Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Known |
| CVE-2017-6334 | NETGEAR | NETGEAR DGN2200 Devices OS Command Injection Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2018-8414 | Microsoft | Microsoft Windows Shell Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2019-0903 | Microsoft | Microsoft GDI Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2019-12991 | Citrix | Citrix SD-WAN and NetScaler Command Injection Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2020-1956 | Apache | Apache Kylin OS Command Injection Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2020-9377 | D-Link | D-Link DIR-610 Devices Remote Command Execution | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2014-3120 | Elastic | Elasticsearch Remote Code Execution Vulnerability | Severity: High CVSS 8.1 | Mar 25, 2022 | Not known |
| CVE-2017-12615 | Apache | Apache Tomcat on Windows Remote Code Execution Vulnerability | Severity: High CVSS 8.1 | Mar 25, 2022 | Known |
| CVE-2017-12617 | Apache | Apache Tomcat Remote Code Execution Vulnerability | Severity: High CVSS 8.1 | Mar 25, 2022 | Not known |
| CVE-2018-6961 | VMware | VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability | Severity: High CVSS 8.1 | Mar 25, 2022 | Not known |
| CVE-2019-6340 | Drupal | Drupal Core Remote Code Execution Vulnerability | Severity: High CVSS 8.1 | Mar 25, 2022 | Not known |
| CVE-2010-4345 | Exim | Exim Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 25, 2022 | Not known |
| CVE-2022-21999 | Microsoft | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 25, 2022 | Known |
| CVE-2010-3035 | Cisco | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability | Severity: High CVSS 7.5 | Mar 25, 2022 | Not known |
| CVE-2014-0130 | Rails | Ruby on Rails Directory Traversal Vulnerability | Severity: High CVSS 7.5 | Mar 25, 2022 | Not known |
| CVE-2015-0666 | Cisco | Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability | Severity: High CVSS 7.5 | Mar 25, 2022 | Not known |
| CVE-2015-3035 | TP-Link | TP-Link Multiple Archer Devices Directory Traversal Vulnerability | Severity: High CVSS 7.5 | Mar 25, 2022 | Not known |
| CVE-2016-0752 | Rails | Ruby on Rails Directory Traversal Vulnerability | Severity: High CVSS 7.5 | Mar 25, 2022 | Not known |
| CVE-2018-8373 | Microsoft | Microsoft Scripting Engine Memory Corruption Vulnerability | Severity: High CVSS 7.5 | Mar 25, 2022 | Not known |
| CVE-2020-5410 | VMware Tanzu | VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability | Severity: High CVSS 7.5 | Mar 25, 2022 | Not known |
| CVE-2016-11021 | D-Link | D-Link DCS-930L Devices OS Command Injection Vulnerability | Severity: High CVSS 7.2 | Mar 25, 2022 | Not known |
| CVE-2019-2616 | Oracle | Oracle BI Publisher Unauthorized Access Vulnerability | Severity: High CVSS 7.2 | Mar 25, 2022 | Not known |
| CVE-2009-2055 | Cisco | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability | Severity: Elevated CVSS 5.9 | Mar 25, 2022 | Not known |
| CVE-2013-5223 | D-Link | D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability | Severity: Elevated CVSS 5.4 | Mar 25, 2022 | Not known |
| CVE-2020-5135 | SonicWall | SonicWall SonicOS Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Mar 15, 2022 | Known |
| CVE-2015-2546 | Microsoft | Microsoft Win32k Memory Corruption Vulnerability | Severity: High CVSS 8.2 | Mar 15, 2022 | Known |
| CVE-2016-3309 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2017-0101 | Microsoft | Microsoft Windows Transaction Manager Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-0543 | Microsoft | Microsoft Windows Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-0841 | Microsoft | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-1064 | Microsoft | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-1069 | Microsoft | Microsoft Task Scheduler Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-1129 | Microsoft | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-1132 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
