1.1%
actively
exploited
exploited
Focus on what’s exploited
Out of 349,964 known CVEs, only 1.1% show real-world exploitation signals.
Data from public sources (including CISA) plus private sensors, enriched with prioritization metadata.
3,823
Total Known exploited
279
Added this week
Search
Results update as you type.
⌘K
Added
Exploitability
Type to search. Filters apply instantly.
| CVE | Severity | Title |
|---|---|---|
| CVE-2021-25298 | 8.8 High |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote
Low complexity
No user interaction
|
| CVE-2021-25297 | 8.8 High |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote
Low complexity
No user interaction
|
| CVE-2021-25296 | 8.8 High |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote
Low complexity
No user interaction
|
| CVE-2021-32648 | 8.2 High |
Account Takeover in Octobercms
Remote
Low complexity
No user interaction
|
| CVE-2020-13927 | 9.8 Critical |
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to...
Remote
Low complexity
No user interaction
|
| CVE-2020-11978 | 8.8 High |
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example...
Remote
Low complexity
No user interaction
|
| CVE-2020-14864 | 7.5 High |
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported...
Remote
Low complexity
No user interaction
|
| CVE-2021-22991 | 9.8 Critical |
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,...
Remote
Low complexity
No user interaction
|
| CVE-2021-21315 | 7.1 High |
Command Injection Vulnerability
Low complexity
No user interaction
|
| CVE-2021-21975 | 7.5 High |
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2021-33766 | 7.3 High |
Microsoft Exchange Server Information Disclosure Vulnerability
Remote
Low complexity
No user interaction
|
| CVE-2021-40870 | 9.8 Critical |
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which...
Remote
Low complexity
No user interaction
|
| CVE-2021-25298 | 8.8 High |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote
Low complexity
No user interaction
|
| CVE-2021-25297 | 8.8 High |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote
Low complexity
No user interaction
|
| CVE-2021-25296 | 8.8 High |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote
Low complexity
No user interaction
|
| CVE-2021-32648 | 8.2 High |
Account Takeover in Octobercms
Remote
Low complexity
No user interaction
|
| CVE-2022-21894 | 4.4 Medium |
Secure Boot Security Feature Bypass Vulnerability
Low complexity
No user interaction
|
| CVE-2013-3900 | 5.5 Medium |
WinVerifyTrust Signature Validation Vulnerability
Low complexity
|
| CVE-2021-27860 | 9.8 Critical |
Arbitrary file upload vulnerability in FatPipe software
Remote
Low complexity
No user interaction
|
| CVE-2019-7609 | 10.0 Critical |
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the...
Remote
Low complexity
No user interaction
|
| CVE-2017-1000486 | 9.8 Critical |
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
Remote
Low complexity
No user interaction
|
| CVE-2015-7450 | 9.8 Critical |
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow...
Remote
Low complexity
No user interaction
|
| CVE-2019-10149 | 9.0 Critical |
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in...
Remote
No user interaction
|
| CVE-2019-1579 | 8.1 High |
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or...
Malware
Remote
No user interaction
|
| CVE-2018-13383 | 4.3 Medium |
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy...
Malware
Remote
Low complexity
No user interaction
|
Displaying vulnerabilities 3001 - 3025 of 3823 in total