Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2023-43000 | Apple | Apple Multiple products Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Mar 5, 2026 | Not known |
| CVE-2021-30952 | Apple | Apple Multiple Products Integer Overflow or Wraparound Vulnerability | Severity: High CVSS 7.8 | Mar 5, 2026 | Not known |
| CVE-2023-41974 | Apple | Apple iOS and iPadOS Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Mar 5, 2026 | Not known |
| CVE-2026-22719 | Broadcom | Broadcom VMware Aria Operations Command Injection Vulnerability | Severity: High CVSS 8.1 | Mar 3, 2026 | Not known |
| CVE-2026-21385 | Qualcomm | Qualcomm Multiple Chipsets Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2026 | Not known |
| CVE-2026-20127 | Cisco | Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability | Severity: Critical CVSS 10.0 | Feb 25, 2026 | Not known |
| CVE-2022-20775 | Cisco | Cisco SD-WAN Path Traversal Vulnerability | Severity: High CVSS 7.8 | Feb 25, 2026 | Not known |
| CVE-2026-25108 | Soliton Systems K.K | Soliton Systems K.K FileZen OS Command Injection Vulnerability | Severity: High CVSS 8.7 | Feb 24, 2026 | Not known |
| CVE-2025-49113 | Roundcube | RoundCube Webmail Deserialization of Untrusted Data Vulnerability | Severity: High CVSS 8.8 | Feb 20, 2026 | Not known |
| CVE-2025-68461 | Roundcube | RoundCube Webmail Cross-site Scripting Vulnerability | Severity: Elevated CVSS 6.1 | Feb 20, 2026 | Not known |
| CVE-2026-22769 | Dell | Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability | Severity: Critical CVSS 10.0 | Feb 18, 2026 | Not known |
| CVE-2021-22175 | GitLab | GitLab Server-Side Request Forgery (SSRF) Vulnerability | Severity: Critical CVSS 9.8 | Feb 18, 2026 | Not known |
| CVE-2020-7796 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability | Severity: Critical CVSS 9.8 | Feb 17, 2026 | Not known |
| CVE-2008-0015 | Microsoft | Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Feb 17, 2026 | Not known |
| CVE-2026-2441 | Google Chromium CSS Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Feb 17, 2026 | Not known | |
| CVE-2024-7694 | TeamT5 | TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability | Severity: High CVSS 7.2 | Feb 17, 2026 | Not known |
| CVE-2026-1731 | BeyondTrust | BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability | Severity: Critical CVSS 9.9 | Feb 13, 2026 | Known |
| CVE-2024-43468 | Microsoft | Microsoft Configuration Manager SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Feb 12, 2026 | Not known |
| CVE-2025-40536 | SolarWinds | SolarWinds Web Help Desk Security Control Bypass Vulnerability | Severity: Critical CVSS 9.8 | Feb 12, 2026 | Not known |
| CVE-2026-20700 | Apple | Apple Multiple Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Feb 12, 2026 | Not known |
| CVE-2025-15556 | Notepad++ | Notepad++ Download of Code Without Integrity Check Vulnerability | Severity: High CVSS 7.7 | Feb 12, 2026 | Not known |
| CVE-2026-21510 | Microsoft | Microsoft Windows Shell Protection Mechanism Failure Vulnerability | Severity: High CVSS 8.8 | Feb 10, 2026 | Not known |
| CVE-2026-21513 | Microsoft | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability | Severity: High CVSS 8.8 | Feb 10, 2026 | Not known |
| CVE-2026-21514 | Microsoft | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability | Severity: High CVSS 7.8 | Feb 10, 2026 | Not known |
| CVE-2026-21519 | Microsoft | Microsoft Windows Type Confusion Vulnerability | Severity: High CVSS 7.8 | Feb 10, 2026 | Not known |
| CVE-2026-21533 | Microsoft | Microsoft Windows Improper Privilege Management Vulnerability | Severity: High CVSS 7.8 | Feb 10, 2026 | Not known |
| CVE-2026-21525 | Microsoft | Microsoft Windows NULL Pointer Dereference Vulnerability | Severity: Elevated CVSS 6.2 | Feb 10, 2026 | Not known |
| CVE-2025-11953 | React Native Community | React Native Community CLI OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Feb 5, 2026 | Not known |
| CVE-2026-24423 | SmarterTools | SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability | Severity: Critical CVSS 9.3 | Feb 5, 2026 | Known |
| CVE-2019-19006 | Sangoma | Sangoma FreePBX Improper Authentication Vulnerability | Severity: Critical CVSS 9.8 | Feb 3, 2026 | Not known |
| CVE-2025-40551 | SolarWinds | SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Feb 3, 2026 | Not known |
| CVE-2025-64328 | Sangoma | Sangoma FreePBX OS Command Injection Vulnerability | Severity: High CVSS 8.6 | Feb 3, 2026 | Not known |
| CVE-2021-39935 | GitLab | GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability | Severity: High CVSS 7.5 | Feb 3, 2026 | Not known |
| CVE-2026-1281 | Ivanti | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | Severity: Critical CVSS 9.8 | Jan 29, 2026 | Not known |
| CVE-2026-24858 | Fortinet | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability | Severity: Critical CVSS 9.8 | Jan 27, 2026 | Not known |
| CVE-2025-52691 | SmarterTools | SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability | Severity: Critical CVSS 10.0 | Jan 26, 2026 | Known |
| CVE-2026-24061 | GNU | GNU InetUtils Argument Injection Vulnerability | Severity: Critical CVSS 9.8 | Jan 26, 2026 | Not known |
| CVE-2026-23760 | SmarterTools | SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability | Severity: Critical CVSS 9.3 | Jan 26, 2026 | Known |
| CVE-2018-14634 | Linux | Linux Kernel Integer Overflow Vulnerability | Severity: High CVSS 7.8 | Jan 26, 2026 | Not known |
| CVE-2026-21509 | Microsoft | Microsoft Office Security Feature Bypass Vulnerability | Severity: High CVSS 7.8 | Jan 26, 2026 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
