1.1%
actively
exploited
exploited
Focus on what’s exploited
Out of 349,964 known CVEs, only 1.1% show real-world exploitation signals.
Data from public sources (including CISA) plus private sensors, enriched with prioritization metadata.
3,824
Total Known exploited
280
Added this week
Search
Results update as you type.
⌘K
Added
Exploitability
Type to search. Filters apply instantly.
| CVE | Severity | Title |
|---|---|---|
| CVE-2018-1000861 | 9.8 Critical |
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in...
Remote
Low complexity
No user interaction
|
| CVE-2017-9791 | 9.8 Critical |
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the...
Remote
Low complexity
No user interaction
|
| CVE-2017-8464 | 8.8 High |
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT...
Remote
Low complexity
|
| CVE-2017-10271 | 7.5 High |
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2017-0263 | 7.8 High |
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT...
Low complexity
No user interaction
|
| CVE-2017-0262 | 7.8 High |
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle...
Low complexity
|
| CVE-2014-4404 | 7.8 High |
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged...
Low complexity
|
| CVE-2015-1130 | 7.8 High |
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via...
Low complexity
No user interaction
|
| CVE-2015-1635 | 9.8 Critical |
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote...
Remote
Low complexity
No user interaction
|
| CVE-2015-2051 | 8.8 High |
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a...
Low complexity
No user interaction
|
| CVE-2016-3088 | 9.8 Critical |
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT...
Remote
Low complexity
No user interaction
|
| CVE-2017-0144 | 8.8 High |
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2017-0145 | 8.8 High |
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2017-0262 | 7.8 High |
Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle...
Low complexity
|
| CVE-2022-21882 | 7.0 High |
Win32k Elevation of Privilege Vulnerability
No user interaction
|
| CVE-2022-21882 | 7.0 High |
Win32k Elevation of Privilege Vulnerability
No user interaction
|
| CVE-2022-23597 | 8.3 High |
Remote program execution with user interaction
Remote
|
| CVE-2022-22587 | 9.8 Critical |
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3,...
Remote
Low complexity
No user interaction
|
| CVE-2021-20038 | 9.8 Critical |
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2020-5722 | 9.8 Critical |
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker...
Remote
Low complexity
No user interaction
|
| CVE-2021-20038 | 9.8 Critical |
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2014-7169 | 9.8 Critical |
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables,...
Remote
Low complexity
No user interaction
|
| CVE-2014-7169 | 9.8 Critical |
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables,...
Remote
Low complexity
No user interaction
|
| CVE-2014-6271 | 9.8 Critical |
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to...
Remote
Low complexity
No user interaction
|
| CVE-2014-1776 | 9.8 Critical |
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of...
Remote
Low complexity
No user interaction
|
Displaying vulnerabilities 2951 - 2975 of 3824 in total