Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
9 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2026-8037 | Progress | Progress LoadMaster Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Aug 7, 2026 | Not known |
| CVE-2024-4885 | Progress | Progress WhatsUp Gold Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Mar 3, 2025 | Not known |
| CVE-2024-1212 | Progress | Progress Kemp LoadMaster OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Nov 18, 2024 | Not known |
| CVE-2024-6670 | Progress | Progress WhatsUp Gold SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Sep 16, 2024 | Known |
| CVE-2024-4358 | Progress | Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability | Severity: Critical CVSS 9.8 | Jun 13, 2024 | Not known |
| CVE-2023-40044 | Progress | Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability | Severity: High CVSS 8.8 | Oct 5, 2023 | Known |
| CVE-2023-34362 | Progress | Progress MOVEit Transfer SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Jun 2, 2023 | Known |
| CVE-2017-9248 | Progress | Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability | Severity: Critical CVSS 9.8 | Nov 3, 2021 | Not known |
| CVE-2019-18935 | Progress | Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability | Severity: Critical CVSS 9.8 | Nov 3, 2021 | Known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
