Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2025-11371 | Gladinet | Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability | Severity: High CVSS 7.5 | Nov 4, 2025 | Not known |
| CVE-2025-24893 | XWiki | XWiki Platform Eval Injection Vulnerability | Severity: Critical CVSS 9.8 | Oct 30, 2025 | Not known |
| CVE-2025-41244 | Broadcom | Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability | Severity: High CVSS 7.8 | Oct 30, 2025 | Not known |
| CVE-2025-6205 | Dassault Systèmes | Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability | Severity: Critical CVSS 9.1 | Oct 28, 2025 | Not known |
| CVE-2025-6204 | Dassault Systèmes | Dassault Systèmes DELMIA Apriso Code Injection Vulnerability | Severity: High CVSS 8.0 | Oct 28, 2025 | Not known |
| CVE-2025-59287 | Microsoft | Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Oct 24, 2025 | Not known |
| CVE-2025-54236 | Adobe | Adobe Commerce and Magento Improper Input Validation Vulnerability | Severity: Critical CVSS 9.1 | Oct 24, 2025 | Not known |
| CVE-2025-61932 | Motex | Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability | Severity: Critical CVSS 9.3 | Oct 22, 2025 | Not known |
| CVE-2025-2746 | Kentico | Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability | Severity: Critical CVSS 9.8 | Oct 20, 2025 | Not known |
| CVE-2025-2747 | Kentico | Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability | Severity: Critical CVSS 9.8 | Oct 20, 2025 | Not known |
| CVE-2022-48503 | Apple | Apple Multiple Products Unspecified Vulnerability | Severity: High CVSS 8.8 | Oct 20, 2025 | Not known |
| CVE-2025-33073 | Microsoft | Microsoft Windows SMB Client Improper Access Control Vulnerability | Severity: High CVSS 8.8 | Oct 20, 2025 | Not known |
| CVE-2025-61884 | Oracle | Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability | Severity: High CVSS 7.5 | Oct 20, 2025 | Known |
| CVE-2025-54253 | Adobe | Adobe Experience Manager Forms Code Execution Vulnerability | Severity: Critical CVSS 10.0 | Oct 15, 2025 | Not known |
| CVE-2016-7836 | SKYSEA | SKYSEA Client View Improper Authentication Vulnerability | Severity: Critical CVSS 9.8 | Oct 14, 2025 | Not known |
| CVE-2025-24990 | Microsoft | Microsoft Windows Untrusted Pointer Dereference Vulnerability | Severity: High CVSS 7.8 | Oct 14, 2025 | Not known |
| CVE-2025-59230 | Microsoft | Microsoft Windows Improper Access Control Vulnerability | Severity: High CVSS 7.8 | Oct 14, 2025 | Not known |
| CVE-2025-47827 | IGEL | IGEL OS Use of a Key Past its Expiration Date Vulnerability | Severity: Elevated CVSS 4.6 | Oct 14, 2025 | Not known |
| CVE-2021-43798 | Grafana Labs | Grafana Path Traversal Vulnerability | Severity: High CVSS 7.5 | Oct 9, 2025 | Not known |
| CVE-2025-27915 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability | Severity: Elevated CVSS 5.4 | Oct 7, 2025 | Not known |
| CVE-2010-3765 | Mozilla | Mozilla Multiple Products Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Oct 6, 2025 | Not known |
| CVE-2025-61882 | Oracle | Oracle E-Business Suite Unspecified Vulnerability | Severity: Critical CVSS 9.8 | Oct 6, 2025 | Known |
| CVE-2011-3402 | Microsoft | Microsoft Windows Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Oct 6, 2025 | Not known |
| CVE-2013-3918 | Microsoft | Microsoft Windows Out-of-Bounds Write Vulnerability | Severity: High CVSS 8.8 | Oct 6, 2025 | Not known |
| CVE-2010-3962 | Microsoft | Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability | Severity: High CVSS 8.1 | Oct 6, 2025 | Not known |
| CVE-2021-22555 | Linux | Linux Kernel Heap Out-of-Bounds Write Vulnerability | Severity: High CVSS 7.8 | Oct 6, 2025 | Not known |
| CVE-2021-43226 | Microsoft | Microsoft Windows Privilege Escalation Vulnerability | Severity: High CVSS 7.8 | Oct 6, 2025 | Known |
| CVE-2015-7755 | Juniper | Juniper ScreenOS Improper Authentication Vulnerability | Severity: Critical CVSS 9.8 | Oct 2, 2025 | Not known |
| CVE-2017-1000353 | Jenkins | Jenkins Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Oct 2, 2025 | Not known |
| CVE-2025-21043 | Samsung | Samsung Mobile Devices Out-of-Bounds Write Vulnerability | Severity: Critical CVSS 9.8 | Oct 2, 2025 | Not known |
| CVE-2014-6278 | GNU | GNU Bash OS Command Injection Vulnerability | Severity: High CVSS 8.8 | Oct 2, 2025 | Not known |
| CVE-2025-4008 | Smartbedded | Smartbedded Meteobridge Command Injection Vulnerability | Severity: High CVSS 8.7 | Oct 2, 2025 | Not known |
| CVE-2025-10035 | Fortra | Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Sep 29, 2025 | Known |
| CVE-2025-32463 | Sudo | Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability | Severity: High CVSS 7.8 | Sep 29, 2025 | Not known |
| CVE-2025-20352 | Cisco | Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability | Severity: High CVSS 7.7 | Sep 29, 2025 | Not known |
| CVE-2021-21311 | Adminer | Adminer Server-Side Request Forgery Vulnerability | Severity: High CVSS 7.2 | Sep 29, 2025 | Not known |
| CVE-2025-59689 | Libraesva | Libraesva Email Security Gateway Command Injection Vulnerability | Severity: Elevated CVSS 6.1 | Sep 29, 2025 | Not known |
| CVE-2025-20333 | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability | Severity: Critical CVSS 9.9 | Sep 25, 2025 | Not known |
| CVE-2025-20362 | Cisco | Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability | Severity: High CVSS 8.6 | Sep 25, 2025 | Not known |
| CVE-2025-10585 | Google Chromium V8 Type Confusion Vulnerability | Severity: Critical CVSS 9.8 | Sep 23, 2025 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
