Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2013-3906 | Microsoft | Microsoft Graphics Component Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Feb 15, 2022 | Not known |
| CVE-2014-1761 | Microsoft | Microsoft Word Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Feb 15, 2022 | Not known |
| CVE-2018-15982 | Adobe | Adobe Flash Player Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Feb 15, 2022 | Known |
| CVE-2018-20250 | RARLAB | WinRAR Absolute Path Traversal Vulnerability | Severity: High CVSS 7.8 | Feb 15, 2022 | Known |
| CVE-2018-8174 | Microsoft | Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability | Severity: High CVSS 7.5 | Feb 15, 2022 | Known |
| CVE-2019-0752 | Microsoft | Microsoft Internet Explorer Type Confusion Vulnerability | Severity: High CVSS 7.5 | Feb 15, 2022 | Known |
| CVE-2022-22620 | Apple | Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Feb 11, 2022 | Not known |
| CVE-2020-0796 | Microsoft | Microsoft SMBv3 Remote Code Execution Vulnerability | Severity: Critical CVSS 10.0 | Feb 10, 2022 | Known |
| CVE-2015-1635 | Microsoft | Microsoft HTTP.sys Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Feb 10, 2022 | Not known |
| CVE-2016-3088 | Apache | Apache ActiveMQ Improper Input Validation Vulnerability | Severity: Critical CVSS 9.8 | Feb 10, 2022 | Not known |
| CVE-2017-9791 | Apache | Apache Struts 1 Improper Input Validation Vulnerability | Severity: Critical CVSS 9.8 | Feb 10, 2022 | Not known |
| CVE-2018-1000861 | Jenkins | Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Feb 10, 2022 | Not known |
| CVE-2015-2051 | D-Link | D-Link DIR-645 Router Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Feb 10, 2022 | Not known |
| CVE-2017-0144 | Microsoft | Microsoft SMBv1 Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Feb 10, 2022 | Known |
| CVE-2017-0145 | Microsoft | Microsoft SMBv1 Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Feb 10, 2022 | Known |
| CVE-2017-8464 | Microsoft | Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Feb 10, 2022 | Not known |
| CVE-2014-4404 | Apple | Apple OS X Heap-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Feb 10, 2022 | Not known |
| CVE-2015-1130 | Apple | Apple OS X Authentication Bypass Vulnerability | Severity: High CVSS 7.8 | Feb 10, 2022 | Not known |
| CVE-2017-0262 | Microsoft | Microsoft Office Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Feb 10, 2022 | Not known |
| CVE-2017-0263 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Feb 10, 2022 | Not known |
| CVE-2021-36934 | Microsoft | Microsoft Windows SAM Local Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Feb 10, 2022 | Not known |
| CVE-2017-10271 | Oracle | Oracle Corporation WebLogic Server Remote Code Execution Vulnerability | Severity: High CVSS 7.5 | Feb 10, 2022 | Known |
| CVE-2022-21882 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Feb 4, 2022 | Known |
| CVE-2014-1776 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: Critical CVSS 9.8 | Jan 28, 2022 | Not known |
| CVE-2014-6271 | GNU | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Jan 28, 2022 | Not known |
| CVE-2014-7169 | GNU | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Jan 28, 2022 | Not known |
| CVE-2017-5689 | Intel | Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability | Severity: Critical CVSS 9.8 | Jan 28, 2022 | Not known |
| CVE-2020-5722 | Grandstream | Grandstream Networks UCM6200 Series SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Jan 28, 2022 | Not known |
| CVE-2021-20038 | SonicWall | SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Jan 28, 2022 | Known |
| CVE-2022-22587 | Apple | Apple Memory Corruption Vulnerability | Severity: Critical CVSS 9.8 | Jan 28, 2022 | Not known |
| CVE-2020-0787 | Microsoft | Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability | Severity: High CVSS 7.8 | Jan 28, 2022 | Known |
| CVE-2012-0391 | Apache | Apache Struts 2 Improper Input Validation Vulnerability | Severity: Critical CVSS 9.8 | Jan 21, 2022 | Not known |
| CVE-2018-8453 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jan 21, 2022 | Known |
| CVE-2006-1547 | Apache | Apache Struts 1 ActionForm Denial-of-Service Vulnerability | Severity: High CVSS 7.5 | Jan 21, 2022 | Not known |
| CVE-2021-35247 | SolarWinds | SolarWinds Serv-U Improper Input Validation Vulnerability | Severity: Elevated CVSS 5.3 | Jan 21, 2022 | Not known |
| CVE-2020-13927 | Apache | Apache Airflow's Experimental API Authentication Bypass | Severity: Critical CVSS 9.8 | Jan 18, 2022 | Not known |
| CVE-2021-22991 | F5 | F5 BIG-IP Traffic Management Microkernel Buffer Overflow | Severity: Critical CVSS 9.8 | Jan 18, 2022 | Not known |
| CVE-2021-40870 | Aviatrix | Aviatrix Controller Unrestricted Upload of File | Severity: Critical CVSS 9.8 | Jan 18, 2022 | Not known |
| CVE-2021-32648 | October CMS | October CMS Improper Authentication | Severity: Critical CVSS 9.1 | Jan 18, 2022 | Not known |
| CVE-2020-11978 | Apache | Apache Airflow Command Injection | Severity: High CVSS 8.8 | Jan 18, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
