Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2020-1380 | Microsoft | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2020-1464 | Microsoft | Microsoft Windows Spoofing Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2020-17087 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2020-24557 | Trend Micro | Trend Micro Multiple Products Improper Access Control Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2020-27930 | Apple | Apple Multiple Products Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2020-27932 | Apple | Apple Multiple Products Type Confusion Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2020-3950 | VMware | VMware Multiple Products Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2020-8655 | EyesOfNetwork | EyesOfNetwork Improper Privilege Management Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2020-9859 | Apple | Apple Multiple Products Code Execution Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-1647 | Microsoft | Microsoft Defender Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-1675 | Microsoft | Microsoft Windows Print Spooler Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Known |
| CVE-2021-1732 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Known |
| CVE-2021-1905 | Qualcomm | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-23874 | McAfee | McAfee Total Protection (MTP) Improper Privilege Management Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-26857 | Microsoft | Microsoft Exchange Server Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Known |
| CVE-2021-26858 | Microsoft | Microsoft Exchange Server Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Known |
| CVE-2021-27065 | Microsoft | Microsoft Exchange Server Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Known |
| CVE-2021-27102 | Accellion | Accellion FTA OS Command Injection Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Known |
| CVE-2021-28310 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-30713 | Apple | Apple macOS Unspecified Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-30807 | Apple | Apple Multiple Products Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-30860 | Apple | Apple Multiple Products Integer Overflow Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-30869 | Apple | Apple iOS, iPadOS, and macOS Type Confusion Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-31956 | Microsoft | Microsoft Windows NTFS Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-31979 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-33771 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-36742 | Trend Micro | Trend Micro Multiple Products Improper Input Validation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-36948 | Microsoft | Microsoft Windows Update Medic Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-36955 | Microsoft | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Known |
| CVE-2021-38645 | Microsoft | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-38648 | Microsoft | Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
| CVE-2021-27059 | Microsoft | Microsoft Office Remote Code Execution Vulnerability | Severity: High CVSS 7.6 | Nov 3, 2021 | Not known |
| CVE-2016-3976 | SAP | SAP NetWeaver Directory Traversal Vulnerability | Severity: High CVSS 7.5 | Nov 3, 2021 | Not known |
| CVE-2018-0296 | Cisco | Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability | Severity: High CVSS 7.5 | Nov 3, 2021 | Not known |
| CVE-2018-15811 | DotNetNuke (DNN) | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability | Severity: High CVSS 7.5 | Nov 3, 2021 | Not known |
| CVE-2018-18325 | DotNetNuke (DNN) | DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability | Severity: High CVSS 7.5 | Nov 3, 2021 | Not known |
| CVE-2018-8653 | Microsoft | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | Severity: High CVSS 7.5 | Nov 3, 2021 | Not known |
| CVE-2019-13608 | Citrix | Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability | Severity: High CVSS 7.5 | Nov 3, 2021 | Known |
| CVE-2019-1367 | Microsoft | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | Severity: High CVSS 7.5 | Nov 3, 2021 | Known |
| CVE-2019-1429 | Microsoft | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | Severity: High CVSS 7.5 | Nov 3, 2021 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
