Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2026-50751 | Check Point | Check Point Security Gateway Improper Authentication Vulnerability | Severity: Critical CVSS 9.3 | Jun 8, 2026 | Known |
| CVE-2026-42271 | BerriAI | BerriAI LiteLLM Command Injection Vulnerability | Severity: High CVSS 8.7 | Jun 8, 2026 | Not known |
| CVE-2026-28318 | SolarWinds | SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability | Severity: High CVSS 7.5 | Jun 5, 2026 | Not known |
| CVE-2026-45247 | Mirasvit | Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.3 | Jun 3, 2026 | Not known |
| CVE-2025-48595 | Android | Android Framework Integer Overflow Vulnerability | Severity: High CVSS 8.4 | Jun 2, 2026 | Not known |
| CVE-2022-0492 | Linux | Linux Kernel Improper Authentication Vulnerability | Severity: High CVSS 7.8 | Jun 2, 2026 | Not known |
| CVE-2024-21182 | Oracle | Oracle WebLogic Server Unspecified Vulnerability | Severity: High CVSS 7.5 | Jun 1, 2026 | Not known |
| CVE-2026-0257 | Palo Alto Networks | Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | Severity: High CVSS 7.8 | May 29, 2026 | Known |
| CVE-2026-45321 | TanStack | TanStack Unspecified Vulnerability | Severity: Critical CVSS 9.6 | May 27, 2026 | Known |
| CVE-2026-48027 | Nx | Nx Console Embedded Malicious Code Vulnerability | Severity: Critical CVSS 9.3 | May 27, 2026 | Known |
| CVE-2026-8398 | Daemon | Daemon Tools Lite Embedded Malicious Code Vulnerability | Severity: Critical CVSS 9.3 | May 27, 2026 | Not known |
| CVE-2026-48172 | LiteSpeed | LiteSpeed cPanel Plugin Privilege Escalation Vulnerability | Severity: Critical CVSS 10.0 | May 26, 2026 | Not known |
| CVE-2026-9082 | Drupal | Drupal Core SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | May 22, 2026 | Not known |
| CVE-2025-34291 | Langflow | Langflow Origin Validation Error Vulnerability | Severity: Critical CVSS 9.4 | May 21, 2026 | Not known |
| CVE-2026-34926 | Trend Micro | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | Severity: Elevated CVSS 6.7 | May 21, 2026 | Not known |
| CVE-2008-4250 | Microsoft | Microsoft Windows Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | May 20, 2026 | Not known |
| CVE-2009-1537 | Microsoft | Microsoft DirectX NULL Byte Overwrite Vulnerability | Severity: High CVSS 8.8 | May 20, 2026 | Not known |
| CVE-2009-3459 | Adobe | Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability | Severity: High CVSS 8.8 | May 20, 2026 | Not known |
| CVE-2010-0249 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.8 | May 20, 2026 | Not known |
| CVE-2010-0806 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.8 | May 20, 2026 | Not known |
| CVE-2026-41091 | Microsoft | Microsoft Defender Link Following Vulnerability | Severity: High CVSS 7.8 | May 20, 2026 | Not known |
| CVE-2026-45498 | Microsoft | Microsoft Defender Denial of Service Vulnerability | Severity: High CVSS 7.5 | May 20, 2026 | Not known |
| CVE-2026-42897 | Microsoft | Microsoft Exchange Server Cross-Site Scripting Vulnerability | Severity: Elevated CVSS 6.1 | May 15, 2026 | Not known |
| CVE-2026-20182 | Cisco | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | Severity: Critical CVSS 10.0 | May 14, 2026 | Not known |
| CVE-2026-42208 | BerriAI | BerriAI LiteLLM SQL Injection Vulnerability | Severity: Critical CVSS 9.3 | May 8, 2026 | Not known |
| CVE-2026-6973 | Ivanti | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability | Severity: High CVSS 7.2 | May 7, 2026 | Not known |
| CVE-2026-0300 | Palo Alto Networks | Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability | Severity: Critical CVSS 9.3 | May 6, 2026 | Not known |
| CVE-2026-31431 | Linux | Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability | Severity: High CVSS 7.8 | May 1, 2026 | Not known |
| CVE-2026-41940 | WebPros | WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability | Severity: Critical CVSS 9.3 | Apr 30, 2026 | Known |
| CVE-2024-1708 | ConnectWise | ConnectWise ScreenConnect Path Traversal Vulnerability | Severity: High CVSS 8.4 | Apr 28, 2026 | Known |
| CVE-2026-32202 | Microsoft | Microsoft Windows Protection Mechanism Failure Vulnerability | Severity: Elevated CVSS 4.3 | Apr 28, 2026 | Not known |
| CVE-2024-57726 | SimpleHelp | SimpleHelp Missing Authorization Vulnerability | Severity: Critical CVSS 9.9 | Apr 24, 2026 | Known |
| CVE-2024-7399 | Samsung | Samsung MagicINFO 9 Server Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Apr 24, 2026 | Not known |
| CVE-2024-57728 | SimpleHelp | SimpleHelp Path Traversal Vulnerability | Severity: High CVSS 7.2 | Apr 24, 2026 | Known |
| CVE-2025-29635 | D-Link | D-Link DIR-823X Command Injection Vulnerability | Severity: High CVSS 7.2 | Apr 24, 2026 | Not known |
| CVE-2026-39987 | Marimo | Marimo Remote Code Execution Vulnerability | Severity: Critical CVSS 9.3 | Apr 23, 2026 | Not known |
| CVE-2026-33825 | Microsoft | Microsoft Defender Insufficient Granularity of Access Control Vulnerability | Severity: High CVSS 7.8 | Apr 22, 2026 | Known |
| CVE-2025-32975 | Quest | Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability | Severity: Critical CVSS 10.0 | Apr 20, 2026 | Not known |
| CVE-2023-27351 | PaperCut | PaperCut NG/MF Improper Authentication Vulnerability | Severity: High CVSS 7.5 | Apr 20, 2026 | Known |
| CVE-2026-20128 | Cisco | Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability | Severity: High CVSS 7.5 | Apr 20, 2026 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
