Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
11 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2025-49113 | Roundcube | RoundCube Webmail Deserialization of Untrusted Data Vulnerability | Severity: High CVSS 8.8 | Feb 20, 2026 | Not known |
| CVE-2025-68461 | Roundcube | RoundCube Webmail Cross-site Scripting Vulnerability | Severity: Elevated CVSS 6.1 | Feb 20, 2026 | Not known |
| CVE-2024-42009 | Roundcube | RoundCube Webmail Cross-Site Scripting Vulnerability | Severity: Critical CVSS 9.3 | Jun 9, 2025 | Not known |
| CVE-2024-37383 | Roundcube | RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Oct 24, 2024 | Not known |
| CVE-2020-13965 | Roundcube | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Jun 26, 2024 | Not known |
| CVE-2023-43770 | Roundcube | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Feb 12, 2024 | Not known |
| CVE-2023-5631 | Roundcube | Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 5.4 | Oct 26, 2023 | Not known |
| CVE-2020-12641 | Roundcube | Roundcube Webmail Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Jun 22, 2023 | Not known |
| CVE-2021-44026 | Roundcube | Roundcube Webmail SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Jun 22, 2023 | Not known |
| CVE-2020-35730 | Roundcube | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Jun 22, 2023 | Not known |
| CVE-2017-16651 | Roundcube | Roundcube Webmail File Disclosure Vulnerability | Severity: High CVSS 7.8 | Nov 3, 2021 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
