Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2024-37079 | Broadcom | Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability | Severity: Critical CVSS 9.8 | Jan 23, 2026 | Not known |
| CVE-2025-34026 | Versa | Versa Concerto Improper Authentication Vulnerability | Severity: Critical CVSS 9.2 | Jan 22, 2026 | Not known |
| CVE-2025-68645 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability | Severity: High CVSS 8.8 | Jan 22, 2026 | Not known |
| CVE-2025-31125 | Vite | Vite Vitejs Improper Access Control Vulnerability | Severity: High CVSS 7.5 | Jan 22, 2026 | Not known |
| CVE-2025-54313 | Prettier | Prettier eslint-config-prettier Embedded Malicious Code Vulnerability | Severity: High CVSS 7.5 | Jan 22, 2026 | Not known |
| CVE-2026-20045 | Cisco | Cisco Unified Communications Products Code Injection Vulnerability | Severity: Critical CVSS 9.8 | Jan 21, 2026 | Not known |
| CVE-2026-20805 | Microsoft | Microsoft Windows Information Disclosure Vulnerability | Severity: Elevated CVSS 5.5 | Jan 13, 2026 | Not known |
| CVE-2025-8110 | Gogs | Gogs Path Traversal Vulnerability | Severity: High CVSS 8.7 | Jan 12, 2026 | Not known |
| CVE-2025-37164 | Hewlett Packard Enterprise (HPE) | Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability | Severity: Critical CVSS 9.8 | Jan 7, 2026 | Not known |
| CVE-2009-0556 | Microsoft | Microsoft Office PowerPoint Code Injection Vulnerability | Severity: High CVSS 8.8 | Jan 7, 2026 | Not known |
| CVE-2025-14847 | MongoDB | MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability | Severity: High CVSS 8.7 | Dec 29, 2025 | Not known |
| CVE-2023-52163 | Digiever | Digiever DS-2105 Pro Missing Authorization Vulnerability | Severity: High CVSS 8.8 | Dec 22, 2025 | Not known |
| CVE-2025-14733 | WatchGuard | WatchGuard Firebox Out of Bounds Write Vulnerability | Severity: Critical CVSS 9.3 | Dec 19, 2025 | Known |
| CVE-2025-20393 | Cisco | Cisco Multiple Products Improper Input Validation Vulnerability | Severity: Critical CVSS 10.0 | Dec 17, 2025 | Not known |
| CVE-2025-59374 | ASUS | ASUS Live Update Embedded Malicious Code Vulnerability | Severity: Critical CVSS 9.3 | Dec 17, 2025 | Not known |
| CVE-2025-40602 | SonicWall | SonicWall SMA1000 Missing Authorization Vulnerability | Severity: Elevated CVSS 6.6 | Dec 17, 2025 | Not known |
| CVE-2025-59718 | Fortinet | Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability | Severity: Critical CVSS 9.8 | Dec 16, 2025 | Not known |
| CVE-2025-43529 | Apple | Apple Multiple Products Use-After-Free WebKit Vulnerability | Severity: High CVSS 8.8 | Dec 15, 2025 | Not known |
| CVE-2025-14611 | Gladinet | Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability | Severity: High CVSS 7.1 | Dec 15, 2025 | Not known |
| CVE-2018-4063 | Sierra Wireless | Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability | Severity: High CVSS 8.8 | Dec 12, 2025 | Not known |
| CVE-2025-14174 | Google Chromium Out of Bounds Memory Access Vulnerability | Severity: High CVSS 8.8 | Dec 12, 2025 | Not known | |
| CVE-2025-58360 | OSGeo | OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability | Severity: Critical CVSS 9.8 | Dec 11, 2025 | Not known |
| CVE-2025-6218 | RARLAB | RARLAB WinRAR Path Traversal Vulnerability | Severity: High CVSS 7.8 | Dec 9, 2025 | Not known |
| CVE-2025-62221 | Microsoft | Microsoft Windows Use After Free Vulnerability | Severity: High CVSS 7.8 | Dec 9, 2025 | Not known |
| CVE-2022-37055 | D-Link | D-Link Routers Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Dec 8, 2025 | Not known |
| CVE-2025-66644 | Array Networks | Array Networks ArrayOS AG OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Dec 8, 2025 | Not known |
| CVE-2025-55182 | Meta | Meta React Server Components Remote Code Execution Vulnerability | Severity: Critical CVSS 10.0 | Dec 5, 2025 | Known |
| CVE-2021-26828 | OpenPLC | OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability | Severity: High CVSS 8.8 | Dec 3, 2025 | Not known |
| CVE-2025-48572 | Android | Android Framework Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Dec 2, 2025 | Not known |
| CVE-2025-48633 | Android | Android Framework Information Disclosure Vulnerability | Severity: Elevated CVSS 5.5 | Dec 2, 2025 | Not known |
| CVE-2021-26829 | OpenPLC | OpenPLC ScadaBR Cross-site Scripting Vulnerability | Severity: Elevated CVSS 5.4 | Nov 28, 2025 | Not known |
| CVE-2025-61757 | Oracle | Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability | Severity: Critical CVSS 9.8 | Nov 21, 2025 | Not known |
| CVE-2025-13223 | Google Chromium V8 Type Confusion Vulnerability | Severity: High CVSS 8.8 | Nov 19, 2025 | Not known | |
| CVE-2025-58034 | Fortinet | Fortinet FortiWeb OS Command Injection Vulnerability | Severity: High CVSS 7.2 | Nov 18, 2025 | Not known |
| CVE-2025-64446 | Fortinet | Fortinet FortiWeb Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Nov 14, 2025 | Not known |
| CVE-2025-9242 | WatchGuard | WatchGuard Firebox Out-of-Bounds Write Vulnerability | Severity: Critical CVSS 9.3 | Nov 12, 2025 | Not known |
| CVE-2025-12480 | Gladinet | Gladinet Triofox Improper Access Control Vulnerability | Severity: Critical CVSS 9.1 | Nov 12, 2025 | Not known |
| CVE-2025-62215 | Microsoft | Microsoft Windows Race Condition Vulnerability | Severity: High CVSS 7.0 | Nov 12, 2025 | Not known |
| CVE-2025-21042 | Samsung | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | Severity: Critical CVSS 9.8 | Nov 10, 2025 | Not known |
| CVE-2025-48703 | CWP | CWP Control Web Panel OS Command Injection Vulnerability | Severity: Critical CVSS 9.0 | Nov 4, 2025 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
