Exploitation dashboard

Actively exploited vulnerabilities

Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.

1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
Reset

9 matching vulnerabilities

Known exploited vulnerabilities, newest first
CVEVendor / productVulnerabilitySeverityAddedRansomware
CVE-2022-28810ZohoZoho ManageEngine ADSelfService Plus Remote Code Execution VulnerabilitySeverity: Elevated
CVSS 6.8
Mar 7, 2023Not known
CVE-2022-47966ZohoZoho ManageEngine Multiple Products Remote Code Execution VulnerabilitySeverity: Critical
CVSS 9.8
Jan 23, 2023 Known
CVE-2022-35405ZohoZoho ManageEngine Multiple Products Remote Code Execution VulnerabilitySeverity: Critical
CVSS 9.8
Sep 22, 2022Not known
CVE-2021-44515ZohoZoho Desktop Central Authentication Bypass VulnerabilitySeverity: Critical
CVSS 9.8
Dec 10, 2021Not known
CVE-2021-37415ZohoZoho ManageEngine ServiceDesk Authentication Bypass VulnerabilitySeverity: Critical
CVSS 9.8
Dec 1, 2021Not known
CVE-2021-44077ZohoZoho ManageEngine ServiceDesk Plus Remote Code Execution VulnerabilitySeverity: Critical
CVSS 9.8
Dec 1, 2021Not known
CVE-2020-10189ZohoZoho ManageEngine Desktop Central File Upload VulnerabilitySeverity: Critical
CVSS 9.8
Nov 3, 2021Not known
CVE-2021-40539ZohoZoho ManageEngine ADSelfService Plus Authentication Bypass VulnerabilitySeverity: Critical
CVSS 9.8
Nov 3, 2021 Known
CVE-2019-8394ZohoZoho ManageEngine ServiceDesk Plus (SDP) File Upload VulnerabilitySeverity: Elevated
CVSS 6.5
Nov 3, 2021Not known

Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.