Exploitation dashboard

Actively exploited vulnerabilities

Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.

1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
Reset

1,734 matching vulnerabilities

Known exploited vulnerabilities, newest first
CVEVendor / productVulnerabilitySeverityAddedRansomware
CVE-2020-13671DrupalDrupal core Un-restricted Upload of FileSeverity: High
CVSS 8.8
Jan 18, 2022Not known
CVE-2021-25296NagiosNagios XI OS Command InjectionSeverity: High
CVSS 8.8
Jan 18, 2022Not known
CVE-2021-25297NagiosNagios XI OS Command InjectionSeverity: High
CVSS 8.8
Jan 18, 2022Not known
CVE-2021-25298NagiosNagios XI OS Command InjectionSeverity: High
CVSS 8.8
Jan 18, 2022Not known
CVE-2021-21315Npm packageSystem Information Library for Node.JS Command InjectionSeverity: High
CVSS 7.8
Jan 18, 2022Not known
CVE-2020-14864OracleOracle Business Intelligence Enterprise Edition Path TransversalSeverity: High
CVSS 7.5
Jan 18, 2022Not known
CVE-2021-21975VMwareVMware Server Side Request Forgery in vRealize Operations Manager APISeverity: High
CVSS 7.5
Jan 18, 2022 Known
CVE-2021-33766MicrosoftMicrosoft Exchange Server Information DisclosureSeverity: High
CVSS 7.3
Jan 18, 2022Not known
CVE-2019-7609ElasticKibana Arbitrary Code ExecutionSeverity: Critical
CVSS 10.0
Jan 10, 2022Not known
CVE-2015-7450IBMIBM WebSphere Application Server and Server Hypervisor Edition Code Injection.Severity: Critical
CVSS 9.8
Jan 10, 2022Not known
CVE-2017-1000486PrimetekPrimetek Primefaces Remote Code Execution VulnerabilitySeverity: Critical
CVSS 9.8
Jan 10, 2022Not known
CVE-2019-10149EximExim Mail Transfer Agent (MTA) Improper Input ValidationSeverity: Critical
CVSS 9.8
Jan 10, 2022Not known
CVE-2019-2725OracleOracle WebLogic Server, InjectionSeverity: Critical
CVSS 9.8
Jan 10, 2022 Known
CVE-2019-9670SynacorSynacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity ReferenceSeverity: Critical
CVSS 9.8
Jan 10, 2022Not known
CVE-2021-36260HikvisionHikvision Improper Input ValidationSeverity: Critical
CVSS 9.8
Jan 10, 2022Not known
CVE-2020-6572GoogleGoogle Chrome Media Use-After-Free VulnerabilitySeverity: High
CVSS 8.8
Jan 10, 2022Not known
CVE-2021-27860FatPipeFatPipe WARP, IPVPN, and MPVPN Configuration Upload exploitSeverity: High
CVSS 8.8
Jan 10, 2022Not known
CVE-2019-1579Palo Alto NetworksPalo Alto Networks PAN-OS Remote Code Execution VulnerabilitySeverity: High
CVSS 8.1
Jan 10, 2022 Known
CVE-2019-1458MicrosoftMicrosoft Win32k Privilege Escalation VulnerabilitySeverity: High
CVSS 7.8
Jan 10, 2022 Known
CVE-2018-13382FortinetFortinet FortiOS and FortiProxy Improper AuthorizationSeverity: High
CVSS 7.5
Jan 10, 2022 Known
CVE-2018-13383FortinetFortinet FortiOS and FortiProxy Out-of-bounds WriteSeverity: Elevated
CVSS 6.5
Jan 10, 2022 Known
CVE-2013-3900MicrosoftMicrosoft WinVerifyTrust function Remote Code ExecutionSeverity: Elevated
CVSS 5.5
Jan 10, 2022Not known
CVE-2021-22017VMwareVMware vCenter Server Improper Access ControlSeverity: Elevated
CVSS 5.3
Jan 10, 2022Not known
CVE-2021-4102GoogleGoogle Chromium V8 Use-After-Free VulnerabilitySeverity: High
CVSS 8.8
Dec 15, 2021Not known
CVE-2021-43890MicrosoftMicrosoft Windows AppX Installer Spoofing VulnerabilitySeverity: High
CVSS 7.1
Dec 15, 2021 Known
CVE-2021-44228ApacheApache Log4j2 Remote Code Execution VulnerabilitySeverity: Critical
CVSS 10.0
Dec 10, 2021 Known
CVE-2019-10758MongoDBMongoDB mongo-express Remote Code Execution VulnerabilitySeverity: Critical
CVSS 9.9
Dec 10, 2021Not known
CVE-2017-12149Red HatRed Hat JBoss Application Server Remote Code Execution VulnerabilitySeverity: Critical
CVSS 9.8
Dec 10, 2021 Known
CVE-2019-7238SonatypeSonatype Nexus Repository Manager Incorrect Access Control VulnerabilitySeverity: Critical
CVSS 9.8
Dec 10, 2021Not known
CVE-2020-17463Fuel CMSFuel CMS SQL Injection VulnerabilitySeverity: Critical
CVSS 9.8
Dec 10, 2021Not known
CVE-2021-35394RealtekRealtek Jungle SDK Remote Code Execution VulnerabilitySeverity: Critical
CVSS 9.8
Dec 10, 2021Not known
CVE-2021-44515ZohoZoho Desktop Central Authentication Bypass VulnerabilitySeverity: Critical
CVSS 9.8
Dec 10, 2021Not known
CVE-2010-1871Red HatRed Hat Linux JBoss Seam 2 Remote Code Execution VulnerabilitySeverity: High
CVSS 8.8
Dec 10, 2021Not known
CVE-2017-17562EmbedthisEmbedthis GoAhead Remote Code Execution VulnerabilitySeverity: High
CVSS 8.1
Dec 10, 2021Not known
CVE-2019-13272LinuxLinux Kernel Improper Privilege Management VulnerabilitySeverity: High
CVSS 7.8
Dec 10, 2021Not known
CVE-2021-44168FortinetFortinet FortiOS Arbitrary File DownloadSeverity: High
CVSS 7.8
Dec 10, 2021Not known
CVE-2019-0193ApacheApache Solr DataImportHandler Code Injection VulnerabilitySeverity: High
CVSS 7.2
Dec 10, 2021Not known
CVE-2020-8816Pi-holePi-Hole AdminLTE Remote Code Execution VulnerabilitySeverity: High
CVSS 7.2
Dec 10, 2021Not known
CVE-2021-37415ZohoZoho ManageEngine ServiceDesk Authentication Bypass VulnerabilitySeverity: Critical
CVSS 9.8
Dec 1, 2021Not known
CVE-2021-44077ZohoZoho ManageEngine ServiceDesk Plus Remote Code Execution VulnerabilitySeverity: Critical
CVSS 9.8
Dec 1, 2021Not known

Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.