Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
19 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2026-83548 | SonicWall | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | Severity: Critical CVSS 10.0 | Sep 2, 2026 | Not known |
| CVE-2026-83549 | SonicWall | SonicWall SMA1000 Appliances OS Command Injection Vulnerability | Severity: High CVSS 7.8 | Sep 2, 2026 | Not known |
| CVE-2026-15409 | SonicWall | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | Severity: Critical CVSS 10.0 | Jul 14, 2026 | Known |
| CVE-2026-15410 | SonicWall | SonicWall SMA1000 Appliances Code Injection Vulnerability | Severity: High CVSS 7.2 | Jul 14, 2026 | Known |
| CVE-2025-40602 | SonicWall | SonicWall SMA1000 Missing Authorization Vulnerability | Severity: Elevated CVSS 6.6 | Dec 17, 2025 | Not known |
| CVE-2023-44221 | SonicWall | SonicWall SMA100 Appliances OS Command Injection Vulnerability | Severity: High CVSS 7.2 | May 1, 2025 | Not known |
| CVE-2021-20035 | SonicWall | SonicWall SMA100 Appliances OS Command Injection Vulnerability | Severity: Elevated CVSS 6.5 | Apr 16, 2025 | Not known |
| CVE-2024-53704 | SonicWall | SonicWall SonicOS SSLVPN Improper Authentication Vulnerability | Severity: Critical CVSS 9.8 | Feb 18, 2025 | Known |
| CVE-2025-23006 | SonicWall | SonicWall SMA1000 Appliances Deserialization Vulnerability | Severity: Critical CVSS 9.8 | Jan 24, 2025 | Known |
| CVE-2024-40766 | SonicWall | SonicWall SonicOS Improper Access Control Vulnerability | Severity: Critical CVSS 9.8 | Sep 9, 2024 | Known |
| CVE-2021-20028 | SonicWall | SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Mar 28, 2022 | Known |
| CVE-2019-7483 | SonicWall | SonicWall SMA100 Directory Traversal Vulnerability | Severity: High CVSS 7.5 | Mar 28, 2022 | Not known |
| CVE-2020-5135 | SonicWall | SonicWall SonicOS Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Mar 15, 2022 | Known |
| CVE-2021-20038 | SonicWall | SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Jan 28, 2022 | Known |
| CVE-2021-20016 | SonicWall | SonicWall SSLVPN SMA100 SQL Injection Vulnerability | Severity: Critical CVSS 9.8 | Nov 3, 2021 | Known |
| CVE-2021-20021 | SonicWall | SonicWall Email Security Improper Privilege Management Vulnerability | Severity: Critical CVSS 9.8 | Nov 3, 2021 | Known |
| CVE-2019-7481 | SonicWall | SonicWall SMA100 SQL Injection Vulnerability | Severity: High CVSS 7.5 | Nov 3, 2021 | Known |
| CVE-2021-20022 | SonicWall | SonicWall Email Security Unrestricted Upload of File Vulnerability | Severity: High CVSS 7.2 | Nov 3, 2021 | Known |
| CVE-2021-20023 | SonicWall | SonicWall Email Security Path Traversal Vulnerability | Severity: Elevated CVSS 4.9 | Nov 3, 2021 | Known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
