Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
1,734 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2025-5086 | Dassault Systèmes | Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.0 | Sep 11, 2025 | Not known |
| CVE-2025-53690 | Sitecore | Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.0 | Sep 4, 2025 | Not known |
| CVE-2025-48543 | Android | Android Runtime Use-After-Free Vulnerability | Severity: High CVSS 8.8 | Sep 4, 2025 | Not known |
| CVE-2025-38352 | Linux | Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability | Severity: High CVSS 7.8 | Sep 4, 2025 | Not known |
| CVE-2025-9377 | TP-Link | TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability | Severity: High CVSS 8.6 | Sep 3, 2025 | Not known |
| CVE-2023-50224 | TP-Link | TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability | Severity: Elevated CVSS 6.5 | Sep 3, 2025 | Not known |
| CVE-2020-24363 | TP-Link | TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability | Severity: High CVSS 8.8 | Sep 2, 2025 | Not known |
| CVE-2025-55177 | Meta Platforms | Meta Platforms WhatsApp Incorrect Authorization Vulnerability | Severity: Elevated CVSS 5.4 | Sep 2, 2025 | Not known |
| CVE-2025-57819 | Sangoma | Sangoma FreePBX Authentication Bypass Vulnerability | Severity: Critical CVSS 10.0 | Aug 29, 2025 | Not known |
| CVE-2025-7775 | Citrix | Citrix NetScaler Memory Overflow Vulnerability | Severity: Critical CVSS 9.2 | Aug 26, 2025 | Not known |
| CVE-2025-48384 | Git | Git Link Following Vulnerability | Severity: High CVSS 8.0 | Aug 25, 2025 | Not known |
| CVE-2024-8068 | Citrix | Citrix Session Recording Improper Privilege Management Vulnerability | Severity: Elevated CVSS 5.1 | Aug 25, 2025 | Not known |
| CVE-2024-8069 | Citrix | Citrix Session Recording Deserialization of Untrusted Data Vulnerability | Severity: Elevated CVSS 5.1 | Aug 25, 2025 | Not known |
| CVE-2025-43300 | Apple | Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability | Severity: Critical CVSS 10.0 | Aug 21, 2025 | Not known |
| CVE-2025-54948 | Trend Micro | Trend Micro Apex One OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Aug 18, 2025 | Not known |
| CVE-2025-8875 | N-able | N-able N-Central Insecure Deserialization Vulnerability | Severity: Critical CVSS 9.4 | Aug 13, 2025 | Not known |
| CVE-2025-8876 | N-able | N-able N-Central Command Injection Vulnerability | Severity: Critical CVSS 9.4 | Aug 13, 2025 | Not known |
| CVE-2007-0671 | Microsoft | Microsoft Office Excel Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Aug 12, 2025 | Not known |
| CVE-2013-3893 | Microsoft | Microsoft Internet Explorer Resource Management Errors Vulnerability | Severity: High CVSS 8.8 | Aug 12, 2025 | Not known |
| CVE-2025-8088 | RARLAB | RARLAB WinRAR Path Traversal Vulnerability | Severity: High CVSS 8.4 | Aug 12, 2025 | Known |
| CVE-2020-25079 | D-Link | D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability | Severity: High CVSS 8.8 | Aug 5, 2025 | Not known |
| CVE-2022-40799 | D-Link | D-Link DNR-322L Download of Code Without Integrity Check Vulnerability | Severity: High CVSS 8.8 | Aug 5, 2025 | Not known |
| CVE-2020-25078 | D-Link | D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability | Severity: High CVSS 7.5 | Aug 5, 2025 | Not known |
| CVE-2025-20281 | Cisco | Cisco Identity Services Engine Injection Vulnerability | Severity: Critical CVSS 10.0 | Jul 28, 2025 | Not known |
| CVE-2025-20337 | Cisco | Cisco Identity Services Engine Injection Vulnerability | Severity: Critical CVSS 10.0 | Jul 28, 2025 | Not known |
| CVE-2023-2533 | PaperCut | PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability | Severity: High CVSS 8.8 | Jul 28, 2025 | Not known |
| CVE-2025-2776 | SysAid | SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability | Severity: Critical CVSS 9.8 | Jul 22, 2025 | Not known |
| CVE-2025-54309 | CrushFTP | CrushFTP Unprotected Alternate Channel Vulnerability | Severity: Critical CVSS 9.8 | Jul 22, 2025 | Not known |
| CVE-2025-49704 | Microsoft | Microsoft SharePoint Code Injection Vulnerability | Severity: High CVSS 8.8 | Jul 22, 2025 | Known |
| CVE-2025-6558 | Google Chromium ANGLE and GPU Improper Input Validation Vulnerability | Severity: High CVSS 8.8 | Jul 22, 2025 | Not known | |
| CVE-2025-2775 | SysAid | SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability | Severity: High CVSS 7.5 | Jul 22, 2025 | Not known |
| CVE-2025-49706 | Microsoft | Microsoft SharePoint Improper Authentication Vulnerability | Severity: Elevated CVSS 6.5 | Jul 22, 2025 | Known |
| CVE-2025-53770 | Microsoft | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Jul 20, 2025 | Known |
| CVE-2025-25257 | Fortinet | Fortinet FortiWeb SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Jul 18, 2025 | Not known |
| CVE-2025-47812 | Wing FTP Server | Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability | Severity: Critical CVSS 10.0 | Jul 14, 2025 | Not known |
| CVE-2025-5777 | Citrix | Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability | Severity: Critical CVSS 9.3 | Jul 10, 2025 | Known |
| CVE-2014-3931 | Looking Glass | Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Jul 7, 2025 | Not known |
| CVE-2016-10033 | PHP | PHPMailer Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Jul 7, 2025 | Not known |
| CVE-2019-5418 | Rails | Rails Ruby on Rails Path Traversal Vulnerability | Severity: High CVSS 7.5 | Jul 7, 2025 | Not known |
| CVE-2019-9621 | Synacor | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability | Severity: High CVSS 7.5 | Jul 7, 2025 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
