Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,733
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
6 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2017-1000353 | Jenkins | Jenkins Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Oct 2, 2025 | Not known |
| CVE-2024-23897 | Jenkins | Jenkins Command Line Interface (CLI) Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Aug 19, 2024 | Known |
| CVE-2015-5317 | Jenkins | Jenkins User Interface (UI) Information Disclosure Vulnerability | Severity: High CVSS 7.5 | May 12, 2023 | Not known |
| CVE-2019-1003029 | Jenkins | Jenkins Script Security Plugin Sandbox Bypass Vulnerability | Severity: Critical CVSS 9.9 | Apr 25, 2022 | Not known |
| CVE-2019-1003030 | Jenkins | Jenkins Matrix Project Plugin Remote Code Execution Vulnerability | Severity: Critical CVSS 9.9 | Mar 25, 2022 | Not known |
| CVE-2018-1000861 | Jenkins | Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Feb 10, 2022 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
