0.7%
actively
exploited
exploited
Focus on what’s exploited
Out of 350,187 known CVEs, only 0.7% show real-world exploitation signals.
Data from public sources (including CISA) plus private sensors, enriched with prioritization metadata.
2,503
Total Known exploited
426
Added this week
Search
Results update as you type.
⌘K
Added
Exploitability
Type to search. Filters apply instantly.
| CVE | Severity | Title |
|---|---|---|
| CVE-2016-4523 | 7.5 High |
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service...
Remote
Low complexity
No user interaction
|
| CVE-2022-22960 | 7.8 High |
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in...
Low complexity
No user interaction
|
| CVE-2022-1364 | 8.8 High |
Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a...
Remote
Low complexity
|
| CVE-2019-3929 | 9.8 Critical |
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W...
Remote
Low complexity
No user interaction
|
| CVE-2019-16057 | 9.8 Critical |
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
Malware
Remote
Low complexity
No user interaction
|
| CVE-2018-7841 | 9.8 Critical |
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper...
Remote
Low complexity
No user interaction
|
| CVE-2014-0780 | 9.8 Critical |
InduSoft Web Studio Path Traversal
Remote
Low complexity
No user interaction
|
| CVE-2010-5330 | 9.8 Critical |
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not...
Remote
Low complexity
No user interaction
|
| CVE-2007-3010 | 9.8 Critical |
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute...
Remote
Low complexity
No user interaction
|
| CVE-2022-22954 | 9.8 Critical |
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2014-9163 | 7.8 High |
Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425...
Low complexity
|
| CVE-2015-0311 | 9.8 Critical |
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through...
Remote
Low complexity
No user interaction
|
| CVE-2022-24521 | 7.8 High |
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Malware
Low complexity
No user interaction
|
| CVE-2018-7602 | 9.8 Critical |
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
Malware
Remote
Low complexity
No user interaction
|
| CVE-2018-20753 | 9.8 Critical |
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2015-5123 | 9.8 Critical |
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on...
Remote
Low complexity
No user interaction
|
| CVE-2015-5122 | 9.8 Critical |
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on...
Remote
Low complexity
No user interaction
|
| CVE-2015-3113 | 9.8 Critical |
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before...
Remote
Low complexity
No user interaction
|
| CVE-2015-0313 | 9.8 Critical |
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before...
Remote
Low complexity
No user interaction
|
| CVE-2015-2502 | 8.8 High |
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a...
Remote
Low complexity
|
| CVE-2017-11317 | 9.8 Critical |
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows...
Remote
Low complexity
No user interaction
|
| CVE-2021-27852 | 9.8 Critical |
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute...
Remote
Low complexity
No user interaction
|
| CVE-2021-22600 | 6.6 Medium |
Double Free in net/packet/af_packet.c leading to priviledge escalation
|
| CVE-2020-2509 | 9.8 Critical |
Command Injection Vulnerability in QTS and QuTS hero
Remote
Low complexity
No user interaction
|
| CVE-2022-23176 | 8.8 High |
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management...
Remote
Low complexity
No user interaction
|
Displaying vulnerabilities 1701 - 1725 of 2503 in total