Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
389 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2019-0703 | Microsoft | Microsoft Windows SMB Information Disclosure Vulnerability | Severity: Elevated CVSS 6.5 | May 23, 2022 | Not known |
| CVE-2014-0322 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.8 | May 4, 2022 | Not known |
| CVE-2014-4113 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | May 4, 2022 | Not known |
| CVE-2021-40450 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 25, 2022 | Not known |
| CVE-2021-41357 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 25, 2022 | Not known |
| CVE-2022-21919 | Microsoft | Microsoft Windows User Profile Service Privilege Escalation Vulnerability | Severity: High CVSS 7.0 | Apr 25, 2022 | Not known |
| CVE-2022-26904 | Microsoft | Microsoft Windows User Profile Service Privilege Escalation Vulnerability | Severity: High CVSS 7.0 | Apr 25, 2022 | Not known |
| CVE-2022-22718 | Microsoft | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 19, 2022 | Not known |
| CVE-2015-2502 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Apr 13, 2022 | Not known |
| CVE-2022-24521 | Microsoft | Microsoft Windows CLFS Driver Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Apr 13, 2022 | Known |
| CVE-2021-42278 | Microsoft | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | Severity: High CVSS 7.5 | Apr 11, 2022 | Known |
| CVE-2021-42287 | Microsoft | Microsoft Active Directory Domain Services Privilege Escalation Vulnerability | Severity: High CVSS 7.5 | Apr 11, 2022 | Known |
| CVE-2021-31166 | Microsoft | Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Apr 6, 2022 | Not known |
| CVE-2017-0148 | Microsoft | Microsoft SMBv1 Server Remote Code Execution Vulnerability | Severity: High CVSS 8.1 | Apr 6, 2022 | Known |
| CVE-2021-34484 | Microsoft | Microsoft Windows User Profile Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 31, 2022 | Not known |
| CVE-2013-2551 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Known |
| CVE-2015-1770 | Microsoft | Microsoft Office Uninitialized Memory Use Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known |
| CVE-2015-2419 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known |
| CVE-2015-2426 | Microsoft | Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known |
| CVE-2016-7200 | Microsoft | Microsoft Edge Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known |
| CVE-2016-7201 | Microsoft | Microsoft Edge Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Mar 28, 2022 | Not known |
| CVE-2017-0037 | Microsoft | Microsoft Edge and Internet Explorer Type Confusion Vulnerability | Severity: High CVSS 8.1 | Mar 28, 2022 | Not known |
| CVE-2010-4398 | Microsoft | Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2011-2005 | Microsoft | Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2012-2539 | Microsoft | Microsoft Word Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2013-3660 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2016-0040 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2016-0151 | Microsoft | Microsoft Windows CSRSS Security Feature Bypass Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Known |
| CVE-2018-8405 | Microsoft | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Known |
| CVE-2018-8406 | Microsoft | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Known |
| CVE-2018-8440 | Microsoft | Microsoft Windows Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Known |
| CVE-2021-34486 | Microsoft | Microsoft Windows Event Tracing Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Not known |
| CVE-2021-38646 | Microsoft | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Mar 28, 2022 | Known |
| CVE-2016-0189 | Microsoft | Microsoft Internet Explorer Memory Corruption Vulnerability | Severity: High CVSS 7.5 | Mar 28, 2022 | Known |
| CVE-2017-0213 | Microsoft | Microsoft Windows Privilege Escalation Vulnerability | Severity: High CVSS 7.3 | Mar 28, 2022 | Known |
| CVE-2017-0059 | Microsoft | Microsoft Internet Explorer Information Disclosure Vulnerability | Severity: Elevated CVSS 4.3 | Mar 28, 2022 | Not known |
| CVE-2014-6324 | Microsoft | Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2014-6332 | Microsoft | Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2017-0146 | Microsoft | Microsoft Windows SMB Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Known |
| CVE-2018-8414 | Microsoft | Microsoft Windows Shell Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
