Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
389 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2019-0903 | Microsoft | Microsoft GDI Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 25, 2022 | Not known |
| CVE-2022-21999 | Microsoft | Microsoft Windows Print Spooler Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 25, 2022 | Known |
| CVE-2018-8373 | Microsoft | Microsoft Scripting Engine Memory Corruption Vulnerability | Severity: High CVSS 7.5 | Mar 25, 2022 | Not known |
| CVE-2015-2546 | Microsoft | Microsoft Win32k Memory Corruption Vulnerability | Severity: High CVSS 8.2 | Mar 15, 2022 | Known |
| CVE-2016-3309 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2017-0101 | Microsoft | Microsoft Windows Transaction Manager Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-0543 | Microsoft | Microsoft Windows Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-0841 | Microsoft | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-1064 | Microsoft | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-1069 | Microsoft | Microsoft Task Scheduler Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-1129 | Microsoft | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-1132 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Not known |
| CVE-2019-1253 | Microsoft | Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-1315 | Microsoft | Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-1322 | Microsoft | Microsoft Windows Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2019-1405 | Microsoft | Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 15, 2022 | Known |
| CVE-2018-8120 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.0 | Mar 15, 2022 | Known |
| CVE-2011-1889 | Microsoft | Microsoft Forefront TMG Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Mar 3, 2022 | Not known |
| CVE-2012-1856 | Microsoft | Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 3, 2022 | Not known |
| CVE-2013-1347 | Microsoft | Microsoft Internet Explorer Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 3, 2022 | Not known |
| CVE-2013-3897 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Mar 3, 2022 | Not known |
| CVE-2015-2424 | Microsoft | Microsoft PowerPoint Memory Corruption Vulnerability | Severity: High CVSS 8.8 | Mar 3, 2022 | Not known |
| CVE-2019-1297 | Microsoft | Microsoft Excel Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Mar 3, 2022 | Not known |
| CVE-2002-0367 | Microsoft | Microsoft Windows Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2004-0210 | Microsoft | Microsoft Windows Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2009-1123 | Microsoft | Microsoft Windows Improper Input Validation Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2009-3129 | Microsoft | Microsoft Excel Featheader Record Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2010-0232 | Microsoft | Microsoft Windows Kernel Exception Handler Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2010-3333 | Microsoft | Microsoft Office Stack-based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2013-5065 | Microsoft | Microsoft Windows Kernel Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2014-4114 | Microsoft | Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2015-1642 | Microsoft | Microsoft Office Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2015-1701 | Microsoft | Microsoft Win32k Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Known |
| CVE-2015-2387 | Microsoft | Microsoft ATM Font Driver Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2015-2545 | Microsoft | Microsoft Office Malformed EPS File Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2016-0099 | Microsoft | Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Known |
| CVE-2016-7193 | Microsoft | Microsoft Office Memory Corruption Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2016-7262 | Microsoft | Microsoft Office Security Feature Bypass Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2017-0001 | Microsoft | Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
| CVE-2017-0261 | Microsoft | Microsoft Office Use-After-Free Vulnerability | Severity: High CVSS 7.8 | Mar 3, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
