Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,733
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
389 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2026-65660 | Microsoft | Microsoft SharePoint Code Injection Vulnerability | Severity: High CVSS 8.8 | Sep 25, 2026 | Not known |
| CVE-2026-81963 | Microsoft | Microsoft Windows Link Following Vulnerability | Severity: High CVSS 7.8 | Sep 8, 2026 | Not known |
| CVE-2026-85880 | Microsoft | Microsoft Windows Heap-Based Buffer Overflow Vulnerability | Severity: High CVSS 7.8 | Sep 8, 2026 | Not known |
| CVE-2019-1068 | Microsoft | Microsoft SQL Server Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Aug 26, 2026 | Not known |
| CVE-2026-33824 | Microsoft | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | Severity: Critical CVSS 9.8 | Aug 18, 2026 | Not known |
| CVE-2026-55040 | Microsoft | Microsoft SharePoint Weak Authentication Vulnerability | Severity: Critical CVSS 9.1 | Aug 18, 2026 | Not known |
| CVE-2026-68820 | Microsoft | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability | Severity: High CVSS 7.0 | Aug 11, 2026 | Not known |
| CVE-2026-50522 | Microsoft | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Jul 22, 2026 | Not known |
| CVE-2026-58644 | Microsoft | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Jul 16, 2026 | Not known |
| CVE-2026-56164 | Microsoft | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | Severity: Critical CVSS 9.8 | Jul 14, 2026 | Not known |
| CVE-2026-56155 | Microsoft | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | Severity: High CVSS 7.8 | Jul 14, 2026 | Not known |
| CVE-2026-45659 | Microsoft | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | Severity: High CVSS 8.8 | Jul 1, 2026 | Known |
| CVE-2008-4250 | Microsoft | Microsoft Windows Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | May 20, 2026 | Not known |
| CVE-2009-1537 | Microsoft | Microsoft DirectX NULL Byte Overwrite Vulnerability | Severity: High CVSS 8.8 | May 20, 2026 | Not known |
| CVE-2010-0249 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.8 | May 20, 2026 | Not known |
| CVE-2010-0806 | Microsoft | Microsoft Internet Explorer Use-After-Free Vulnerability | Severity: High CVSS 8.8 | May 20, 2026 | Not known |
| CVE-2026-41091 | Microsoft | Microsoft Defender Link Following Vulnerability | Severity: High CVSS 7.8 | May 20, 2026 | Not known |
| CVE-2026-45498 | Microsoft | Microsoft Defender Denial of Service Vulnerability | Severity: High CVSS 7.5 | May 20, 2026 | Not known |
| CVE-2026-42897 | Microsoft | Microsoft Exchange Server Cross-Site Scripting Vulnerability | Severity: Elevated CVSS 6.1 | May 15, 2026 | Not known |
| CVE-2026-32202 | Microsoft | Microsoft Windows Protection Mechanism Failure Vulnerability | Severity: Elevated CVSS 4.3 | Apr 28, 2026 | Not known |
| CVE-2026-33825 | Microsoft | Microsoft Defender Insufficient Granularity of Access Control Vulnerability | Severity: High CVSS 7.8 | Apr 22, 2026 | Known |
| CVE-2009-0238 | Microsoft | Microsoft Office Remote Code Execution | Severity: High CVSS 8.8 | Apr 14, 2026 | Not known |
| CVE-2026-32201 | Microsoft | Microsoft SharePoint Server Improper Input Validation Vulnerability | Severity: Elevated CVSS 6.5 | Apr 14, 2026 | Not known |
| CVE-2023-21529 | Microsoft | Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability | Severity: High CVSS 8.8 | Apr 13, 2026 | Known |
| CVE-2012-1854 | Microsoft | Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability | Severity: High CVSS 7.8 | Apr 13, 2026 | Not known |
| CVE-2023-36424 | Microsoft | Microsoft Windows Out-of-Bounds Read Vulnerability | Severity: High CVSS 7.8 | Apr 13, 2026 | Not known |
| CVE-2025-60710 | Microsoft | Microsoft Windows Link Following Vulnerability | Severity: High CVSS 7.8 | Apr 13, 2026 | Known |
| CVE-2026-20963 | Microsoft | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Mar 18, 2026 | Not known |
| CVE-2008-0015 | Microsoft | Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability | Severity: High CVSS 8.8 | Feb 17, 2026 | Not known |
| CVE-2024-43468 | Microsoft | Microsoft Configuration Manager SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Feb 12, 2026 | Not known |
| CVE-2026-21510 | Microsoft | Microsoft Windows Shell Protection Mechanism Failure Vulnerability | Severity: High CVSS 8.8 | Feb 10, 2026 | Not known |
| CVE-2026-21513 | Microsoft | Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability | Severity: High CVSS 8.8 | Feb 10, 2026 | Not known |
| CVE-2026-21514 | Microsoft | Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability | Severity: High CVSS 7.8 | Feb 10, 2026 | Not known |
| CVE-2026-21519 | Microsoft | Microsoft Windows Type Confusion Vulnerability | Severity: High CVSS 7.8 | Feb 10, 2026 | Not known |
| CVE-2026-21533 | Microsoft | Microsoft Windows Improper Privilege Management Vulnerability | Severity: High CVSS 7.8 | Feb 10, 2026 | Not known |
| CVE-2026-21525 | Microsoft | Microsoft Windows NULL Pointer Dereference Vulnerability | Severity: Elevated CVSS 6.2 | Feb 10, 2026 | Not known |
| CVE-2026-21509 | Microsoft | Microsoft Office Security Feature Bypass Vulnerability | Severity: High CVSS 7.8 | Jan 26, 2026 | Not known |
| CVE-2026-20805 | Microsoft | Microsoft Windows Information Disclosure Vulnerability | Severity: Elevated CVSS 5.5 | Jan 13, 2026 | Not known |
| CVE-2009-0556 | Microsoft | Microsoft Office PowerPoint Code Injection Vulnerability | Severity: High CVSS 8.8 | Jan 7, 2026 | Not known |
| CVE-2025-62221 | Microsoft | Microsoft Windows Use After Free Vulnerability | Severity: High CVSS 7.8 | Dec 9, 2025 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
