Exploitation dashboard
Actively exploited vulnerabilities
Every vulnerability here has reliable evidence of exploitation in the wild, based on the CISA Known Exploited Vulnerabilities catalog. If you run an affected product, patch or mitigate it first.
1,734
Known exploited (all time)
39
Added in last 30 days
361
Used by ransomware
13 matching vulnerabilities
| CVE | Vendor / product | Vulnerability | Severity | Added | Ransomware |
|---|---|---|---|---|---|
| CVE-2026-7273 | Zyxel | Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability | Severity: High CVSS 8.8 | Sep 21, 2026 | Not known |
| CVE-2024-40890 | Zyxel | Zyxel DSL CPE OS Command Injection Vulnerability | Severity: High CVSS 8.8 | Feb 11, 2025 | Not known |
| CVE-2024-40891 | Zyxel | Zyxel DSL CPE OS Command Injection Vulnerability | Severity: High CVSS 8.8 | Feb 11, 2025 | Not known |
| CVE-2024-11667 | Zyxel | Zyxel Multiple Firewalls Path Traversal Vulnerability | Severity: Critical CVSS 9.8 | Dec 3, 2024 | Known |
| CVE-2017-6884 | Zyxel | Zyxel EMG2926 Routers Command Injection Vulnerability | Severity: High CVSS 8.8 | Sep 18, 2023 | Known |
| CVE-2017-18368 | Zyxel | Zyxel P660HN-T1A Routers Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Aug 7, 2023 | Not known |
| CVE-2023-27992 | Zyxel | Zyxel Multiple NAS Devices Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Jun 23, 2023 | Not known |
| CVE-2023-33009 | Zyxel | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Jun 5, 2023 | Not known |
| CVE-2023-33010 | Zyxel | Zyxel Multiple Firewalls Buffer Overflow Vulnerability | Severity: Critical CVSS 9.8 | Jun 5, 2023 | Not known |
| CVE-2023-28771 | Zyxel | Zyxel Multiple Firewalls OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | May 31, 2023 | Not known |
| CVE-2022-30525 | Zyxel | Zyxel Multiple Firewalls OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | May 16, 2022 | Not known |
| CVE-2020-9054 | Zyxel | Zyxel Multiple NAS Devices OS Command Injection Vulnerability | Severity: Critical CVSS 9.8 | Mar 25, 2022 | Not known |
| CVE-2020-29583 | Zyxel | Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability | Severity: Critical CVSS 9.8 | Nov 3, 2021 | Not known |
Source: CISA Known Exploited Vulnerabilities catalog (US government, public domain), refreshed hourly. CVSS scores from the NIST National Vulnerability Database are added as they are fetched.
