Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2020-13671 | Drupal | Drupal core Un-restricted Upload of File | Severity: High CVSS 8.8 | Jan 18, 2022 | Not known |
| CVE-2021-25296 | Nagios | Nagios XI OS Command Injection | Severity: High CVSS 8.8 | Jan 18, 2022 | Not known |
| CVE-2021-25297 | Nagios | Nagios XI OS Command Injection | Severity: High CVSS 8.8 | Jan 18, 2022 | Not known |
| CVE-2021-25298 | Nagios | Nagios XI OS Command Injection | Severity: High CVSS 8.8 | Jan 18, 2022 | Not known |
| CVE-2021-21315 | Npm package | System Information Library for Node.JS Command Injection | Severity: High CVSS 7.8 | Jan 18, 2022 | Not known |
| CVE-2020-14864 | Oracle | Oracle Business Intelligence Enterprise Edition Path Transversal | Severity: High CVSS 7.5 | Jan 18, 2022 | Not known |
| CVE-2021-21975 | VMware | VMware Server Side Request Forgery in vRealize Operations Manager API | Severity: High CVSS 7.5 | Jan 18, 2022 | Known |
| CVE-2021-33766 | Microsoft | Microsoft Exchange Server Information Disclosure | Severity: High CVSS 7.3 | Jan 18, 2022 | Not known |
| CVE-2019-7609 | Elastic | Kibana Arbitrary Code Execution | Severity: Critical CVSS 10.0 | Jan 10, 2022 | Not known |
| CVE-2015-7450 | IBM | IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. | Severity: Critical CVSS 9.8 | Jan 10, 2022 | Not known |
| CVE-2017-1000486 | Primetek | Primetek Primefaces Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Jan 10, 2022 | Not known |
| CVE-2019-10149 | Exim | Exim Mail Transfer Agent (MTA) Improper Input Validation | Severity: Critical CVSS 9.8 | Jan 10, 2022 | Not known |
| CVE-2019-2725 | Oracle | Oracle WebLogic Server, Injection | Severity: Critical CVSS 9.8 | Jan 10, 2022 | Known |
| CVE-2019-9670 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference | Severity: Critical CVSS 9.8 | Jan 10, 2022 | Not known |
| CVE-2021-36260 | Hikvision | Hikvision Improper Input Validation | Severity: Critical CVSS 9.8 | Jan 10, 2022 | Not known |
| CVE-2020-6572 | Google Chrome Media Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Jan 10, 2022 | Not known | |
| CVE-2021-27860 | FatPipe | FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit | Severity: High CVSS 8.8 | Jan 10, 2022 | Not known |
| CVE-2019-1579 | Palo Alto Networks | Palo Alto Networks PAN-OS Remote Code Execution Vulnerability | Severity: High CVSS 8.1 | Jan 10, 2022 | Known |
| CVE-2019-1458 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jan 10, 2022 | Known |
| CVE-2018-13382 | Fortinet | Fortinet FortiOS and FortiProxy Improper Authorization | Severity: High CVSS 7.5 | Jan 10, 2022 | Known |
| CVE-2018-13383 | Fortinet | Fortinet FortiOS and FortiProxy Out-of-bounds Write | Severity: Elevated CVSS 6.5 | Jan 10, 2022 | Known |
| CVE-2013-3900 | Microsoft | Microsoft WinVerifyTrust function Remote Code Execution | Severity: Elevated CVSS 5.5 | Jan 10, 2022 | Not known |
| CVE-2021-22017 | VMware | VMware vCenter Server Improper Access Control | Severity: Elevated CVSS 5.3 | Jan 10, 2022 | Not known |
| CVE-2021-4102 | Google Chromium V8 Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Dec 15, 2021 | Not known | |
| CVE-2021-43890 | Microsoft | Microsoft Windows AppX Installer Spoofing Vulnerability | Severity: High CVSS 7.1 | Dec 15, 2021 | Known |
| CVE-2021-44228 | Apache | Apache Log4j2 Remote Code Execution Vulnerability | Severity: Critical CVSS 10.0 | Dec 10, 2021 | Known |
| CVE-2019-10758 | MongoDB | MongoDB mongo-express Remote Code Execution Vulnerability | Severity: Critical CVSS 9.9 | Dec 10, 2021 | Not known |
| CVE-2017-12149 | Red Hat | Red Hat JBoss Application Server Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Dec 10, 2021 | Known |
| CVE-2019-7238 | Sonatype | Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability | Severity: Critical CVSS 9.8 | Dec 10, 2021 | Not known |
| CVE-2020-17463 | Fuel CMS | Fuel CMS SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Dec 10, 2021 | Not known |
| CVE-2021-35394 | Realtek | Realtek Jungle SDK Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Dec 10, 2021 | Not known |
| CVE-2021-44515 | Zoho | Zoho Desktop Central Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Dec 10, 2021 | Not known |
| CVE-2010-1871 | Red Hat | Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Dec 10, 2021 | Not known |
| CVE-2017-17562 | Embedthis | Embedthis GoAhead Remote Code Execution Vulnerability | Severity: High CVSS 8.1 | Dec 10, 2021 | Not known |
| CVE-2019-13272 | Linux | Linux Kernel Improper Privilege Management Vulnerability | Severity: High CVSS 7.8 | Dec 10, 2021 | Not known |
| CVE-2021-44168 | Fortinet | Fortinet FortiOS Arbitrary File Download | Severity: High CVSS 7.8 | Dec 10, 2021 | Not known |
| CVE-2019-0193 | Apache | Apache Solr DataImportHandler Code Injection Vulnerability | Severity: High CVSS 7.2 | Dec 10, 2021 | Not known |
| CVE-2020-8816 | Pi-hole | Pi-Hole AdminLTE Remote Code Execution Vulnerability | Severity: High CVSS 7.2 | Dec 10, 2021 | Not known |
| CVE-2021-37415 | Zoho | Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Dec 1, 2021 | Not known |
| CVE-2021-44077 | Zoho | Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Dec 1, 2021 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
