Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
9 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2022-28810 | Zoho | Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability | Severity: Elevated CVSS 6.8 | Mar 7, 2023 | Not known |
| CVE-2022-47966 | Zoho | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Jan 23, 2023 | Known |
| CVE-2022-35405 | Zoho | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Sep 22, 2022 | Not known |
| CVE-2021-44515 | Zoho | Zoho Desktop Central Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Dec 10, 2021 | Not known |
| CVE-2021-37415 | Zoho | Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Dec 1, 2021 | Not known |
| CVE-2021-44077 | Zoho | Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability | Severity: Critical CVSS 9.8 | Dec 1, 2021 | Not known |
| CVE-2020-10189 | Zoho | Zoho ManageEngine Desktop Central File Upload Vulnerability | Severity: Critical CVSS 9.8 | Nov 3, 2021 | Not known |
| CVE-2021-40539 | Zoho | Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability | Severity: Critical CVSS 9.8 | Nov 3, 2021 | Known |
| CVE-2019-8394 | Zoho | Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability | Severity: Elevated CVSS 6.5 | Nov 3, 2021 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
