Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,733
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
389 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2023-28229 | Microsoft | Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability | Severity: High CVSS 7.0 | Oct 4, 2023 | Not known |
| CVE-2023-36802 | Microsoft | Microsoft Streaming Service Proxy Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Sep 12, 2023 | Not known |
| CVE-2023-36761 | Microsoft | Microsoft Word Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | Sep 12, 2023 | Not known |
| CVE-2023-38180 | Microsoft | Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability | Severity: High CVSS 7.5 | Aug 9, 2023 | Not known |
| CVE-2023-36884 | Microsoft | Microsoft Windows Search Remote Code Execution Vulnerability | Severity: High CVSS 7.5 | Jul 17, 2023 | Known |
| CVE-2023-32049 | Microsoft | Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability | Severity: High CVSS 8.8 | Jul 11, 2023 | Not known |
| CVE-2023-35311 | Microsoft | Microsoft Outlook Security Feature Bypass Vulnerability | Severity: High CVSS 8.8 | Jul 11, 2023 | Not known |
| CVE-2023-32046 | Microsoft | Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jul 11, 2023 | Not known |
| CVE-2023-36874 | Microsoft | Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jul 11, 2023 | Not known |
| CVE-2016-0165 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jun 22, 2023 | Not known |
| CVE-2023-29336 | Microsoft | Microsoft Win32K Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 9, 2023 | Not known |
| CVE-2023-28252 | Microsoft | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 11, 2023 | Known |
| CVE-2019-1388 | Microsoft | Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 7, 2023 | Known |
| CVE-2013-3163 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Mar 30, 2023 | Not known |
| CVE-2023-23397 | Microsoft | Microsoft Office Outlook Privilege Escalation Vulnerability | Severity: Critical CVSS 9.8 | Mar 14, 2023 | Not known |
| CVE-2023-24880 | Microsoft | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability | Severity: Elevated CVSS 4.4 | Mar 14, 2023 | Known |
| CVE-2023-21823 | Microsoft | Microsoft Windows Graphic Component Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Feb 14, 2023 | Not known |
| CVE-2023-23376 | Microsoft | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Feb 14, 2023 | Known |
| CVE-2023-21715 | Microsoft | Microsoft Office Publisher Security Feature Bypass Vulnerability | Severity: High CVSS 7.3 | Feb 14, 2023 | Not known |
| CVE-2022-41080 | Microsoft | Microsoft Exchange Server Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | Jan 10, 2023 | Known |
| CVE-2023-21674 | Microsoft | Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | Jan 10, 2023 | Not known |
| CVE-2022-44698 | Microsoft | Microsoft Defender SmartScreen Security Feature Bypass Vulnerability | Severity: Elevated CVSS 5.4 | Dec 13, 2022 | Known |
| CVE-2022-41049 | Microsoft | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability | Severity: Elevated CVSS 5.4 | Nov 14, 2022 | Not known |
| CVE-2022-41128 | Microsoft | Microsoft Windows Scripting Languages Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Nov 8, 2022 | Not known |
| CVE-2022-41073 | Microsoft | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 8, 2022 | Known |
| CVE-2022-41125 | Microsoft | Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 8, 2022 | Not known |
| CVE-2022-41091 | Microsoft | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability | Severity: Elevated CVSS 5.4 | Nov 8, 2022 | Known |
| CVE-2022-41033 | Microsoft | Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Oct 11, 2022 | Not known |
| CVE-2022-41040 | Microsoft | Microsoft Exchange Server Server-Side Request Forgery Vulnerability | Severity: High CVSS 8.8 | Sep 30, 2022 | Known |
| CVE-2022-41082 | Microsoft | Microsoft Exchange Server Remote Code Execution Vulnerability | Severity: High CVSS 8.0 | Sep 30, 2022 | Known |
| CVE-2010-2568 | Microsoft | Microsoft Windows Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Sep 15, 2022 | Not known |
| CVE-2022-37969 | Microsoft | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Sep 14, 2022 | Known |
| CVE-2022-26923 | Microsoft | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | Aug 18, 2022 | Not known |
| CVE-2022-21971 | Microsoft | Microsoft Windows Runtime Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Aug 18, 2022 | Not known |
| CVE-2022-34713 | Microsoft | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Aug 9, 2022 | Not known |
| CVE-2022-22047 | Microsoft | Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Jul 12, 2022 | Not known |
| CVE-2022-26925 | Microsoft | Microsoft Windows LSA Spoofing Vulnerability | Severity: Elevated CVSS 5.9 | Jul 1, 2022 | Not known |
| CVE-2022-30190 | Microsoft | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Jun 14, 2022 | Known |
| CVE-2006-2492 | Microsoft | Microsoft Word Malformed Object Pointer Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known |
| CVE-2012-1889 | Microsoft | Microsoft XML Core Services Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Jun 8, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
