Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
389 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2012-4969 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.1 | Jun 8, 2022 | Not known |
| CVE-2009-0557 | Microsoft | Microsoft Office Object Record Corruption Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2009-0563 | Microsoft | Microsoft Office Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2010-2572 | Microsoft | Microsoft PowerPoint Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2012-0151 | Microsoft | Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2013-1331 | Microsoft | Microsoft Office Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Jun 8, 2022 | Not known |
| CVE-2014-2817 | Microsoft | Microsoft Internet Explorer Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2014-4123 | Microsoft | Microsoft Internet Explorer Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2014-4148 | Microsoft | Microsoft Windows Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2015-2360 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2015-2425 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2016-0034 | Microsoft | Microsoft Silverlight Runtime Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Known |
| CVE-2016-7256 | Microsoft | Microsoft Windows Open Type Font Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | May 25, 2022 | Not known |
| CVE-2013-0074 | Microsoft | Microsoft Silverlight Double Dereference Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Known |
| CVE-2014-4077 | Microsoft | Microsoft IME Japanese Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2015-0016 | Microsoft | Microsoft Windows TS WebProxy Directory Traversal Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2015-1671 | Microsoft | Microsoft Windows Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2015-6175 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2016-3393 | Microsoft | Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | May 25, 2022 | Not known |
| CVE-2015-1769 | Microsoft | Microsoft Windows Mount Manager Privilege Escalation Vulnerability | Severity: Elevated CVSS 6.6 | May 25, 2022 | Not known |
| CVE-2013-7331 | Microsoft | Microsoft Internet Explorer Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 25, 2022 | Not known |
| CVE-2015-0071 | Microsoft | Microsoft Internet Explorer ASLR Bypass Vulnerability | Severity: Elevated CVSS 6.5 | May 25, 2022 | Not known |
| CVE-2013-3896 | Microsoft | Microsoft Silverlight Information Disclosure Vulnerability | Severity: Elevated CVSS 5.5 | May 25, 2022 | Not known |
| CVE-2017-8543 | Microsoft | Microsoft Windows Search Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | May 24, 2022 | Not known |
| CVE-2017-0149 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: High CVSS 8.8 | May 24, 2022 | Not known |
| CVE-2017-0210 | Microsoft | Microsoft Internet Explorer Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | May 24, 2022 | Not known |
| CVE-2017-0005 | Microsoft | Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 24, 2022 | Not known |
| CVE-2018-8611 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 24, 2022 | Not known |
| CVE-2017-0147 | Microsoft | Microsoft Windows SMBv1 Information Disclosure Vulnerability | Severity: High CVSS 7.5 | May 24, 2022 | Known |
| CVE-2016-3298 | Microsoft | Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 24, 2022 | Not known |
| CVE-2016-3351 | Microsoft | Microsoft Internet Explorer and Edge Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 24, 2022 | Known |
| CVE-2017-0022 | Microsoft | Microsoft XML Core Services Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 24, 2022 | Not known |
| CVE-2016-0162 | Microsoft | Microsoft Internet Explorer Information Disclosure Vulnerability | Severity: Elevated CVSS 4.3 | May 24, 2022 | Not known |
| CVE-2018-8589 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Not known |
| CVE-2019-0880 | Microsoft | Microsoft Windows Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Not known |
| CVE-2019-1130 | Microsoft | Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Known |
| CVE-2019-1385 | Microsoft | Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Known |
| CVE-2020-0638 | Microsoft | Microsoft Update Notification Manager Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Known |
| CVE-2020-1027 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 23, 2022 | Not known |
| CVE-2019-0676 | Microsoft | Microsoft Internet Explorer Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 23, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
