Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2016-3718 | ImageMagick | ImageMagick Server-Side Request Forgery (SSRF) Vulnerability | Severity: Elevated CVSS 5.5 | Nov 3, 2021 | Not known |
| CVE-2020-1472 | Microsoft | Microsoft Netlogon Privilege Escalation Vulnerability | Severity: Elevated CVSS 5.5 | Nov 3, 2021 | Known |
| CVE-2020-27950 | Apple | Apple Multiple Products Memory Initialization Vulnerability | Severity: Elevated CVSS 5.5 | Nov 3, 2021 | Not known |
| CVE-2021-1906 | Qualcomm | Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability | Severity: Elevated CVSS 5.5 | Nov 3, 2021 | Not known |
| CVE-2021-27562 | Arm | Arm Trusted Firmware Out-of-Bounds Write Vulnerability | Severity: Elevated CVSS 5.5 | Nov 3, 2021 | Not known |
| CVE-2021-30657 | Apple | Apple macOS Unspecified Vulnerability | Severity: Elevated CVSS 5.5 | Nov 3, 2021 | Not known |
| CVE-2021-31955 | Microsoft | Microsoft Windows Kernel Information Disclosure Vulnerability | Severity: Elevated CVSS 5.5 | Nov 3, 2021 | Not known |
| CVE-2021-31199 | Microsoft | Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability | Severity: Elevated CVSS 5.2 | Nov 3, 2021 | Not known |
| CVE-2021-31201 | Microsoft | Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability | Severity: Elevated CVSS 5.2 | Nov 3, 2021 | Not known |
| CVE-2021-20023 | SonicWall | SonicWall Email Security Path Traversal Vulnerability | Severity: Elevated CVSS 4.9 | Nov 3, 2021 | Known |
| CVE-2020-4430 | IBM | IBM Data Risk Manager Directory Traversal Vulnerability | Severity: Elevated CVSS 4.3 | Nov 3, 2021 | Not known |
| CVE-2020-8196 | Citrix | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | Severity: Elevated CVSS 4.3 | Nov 3, 2021 | Not known |
| CVE-2020-9819 | Apple | Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability | Severity: Elevated CVSS 4.3 | Nov 3, 2021 | Not known |
| CVE-2020-0878 | Microsoft | Microsoft Edge and Internet Explorer Memory Corruption Vulnerability | Severity: Elevated CVSS 4.2 | Nov 3, 2021 | Known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
