Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
6 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2026-87902 | WordPress | WordPress Core Remote File Inclusion Vulnerability | Severity: High CVSS 8.1 | Sep 25, 2026 | Not known |
| CVE-2026-63030 | WordPress | WordPress Core Interpretation Conflict Vulnerability | Severity: Critical CVSS 9.8 | Jul 21, 2026 | Not known |
| CVE-2026-60137 | WordPress | WordPress Core SQL Injection Vulnerability | Severity: Elevated CVSS 5.9 | Jul 21, 2026 | Not known |
| CVE-2020-25213 | WordPress | WordPress File Manager Plugin Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Nov 3, 2021 | Not known |
| CVE-2020-11738 | WordPress | WordPress Snap Creek Duplicator Plugin File Download Vulnerability | Severity: High CVSS 7.5 | Nov 3, 2021 | Not known |
| CVE-2019-9978 | WordPress | WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability | Severity: Elevated CVSS 6.1 | Nov 3, 2021 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
