KEVIntel
0.7%
actively
exploited

Focus on what’s exploited

Out of 350,187 known CVEs, only 0.7% show real-world exploitation signals.

Data from public sources (including CISA) plus private sensors, enriched with prioritization metadata.

2,503
Total Known exploited
426
Added this week

Search

Added
Exploitability

Type to search. Filters apply instantly.

CVE Severity Title
CVE-2018-0147 9.8 Critical
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an...
Remote Low complexity No user interaction
CVE-2016-4171 9.8 Critical
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as...
Remote Low complexity No user interaction
CVE-2016-1555 9.8 Critical
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and...
Remote Low complexity No user interaction
CVE-2016-11021 7.2 High
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
Remote Low complexity No user interaction
CVE-2016-10174 9.8 Critical
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This...
Remote Low complexity No user interaction
CVE-2016-0752 7.5 High
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x...
Remote Low complexity No user interaction
CVE-2015-4068 9.1 Critical
Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of...
Remote Low complexity No user interaction
CVE-2015-3035 7.5 High
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with...
Remote Low complexity No user interaction
CVE-2015-1427 9.8 Critical
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism...
Remote Low complexity No user interaction
CVE-2015-1187 9.8 Critical
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
Remote Low complexity No user interaction
CVE-2015-0666 7.5 High
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers...
Remote Low complexity No user interaction
CVE-2014-6332 8.8 High
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows...
Remote Low complexity
CVE-2014-6324 8.8 High
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7...
Remote Low complexity No user interaction
CVE-2014-6287 9.8 Critical
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to...
Remote Low complexity No user interaction
CVE-2014-3120 8.1 High
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL...
Remote Low complexity No user interaction
CVE-2014-0130 7.5 High
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before...
Remote Low complexity No user interaction
CVE-2013-5223 5.4 Medium
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web...
Remote Low complexity
CVE-2013-4810 9.8 Critical
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote...
Remote Low complexity No user interaction
CVE-2013-2251 9.8 Critical
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2)...
Remote Low complexity No user interaction
CVE-2012-1823 9.8 Critical
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query...
Remote Low complexity No user interaction
CVE-2010-4345 7.8 High
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate...
Low complexity No user interaction
CVE-2010-4344 9.8 Critical
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an...
Remote Low complexity No user interaction
CVE-2010-3035 7.5 High
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers...
Remote Low complexity No user interaction
CVE-2010-2861 9.8 Critical
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read...
Malware Remote Low complexity No user interaction
CVE-2009-2055 5.9 Medium
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid...
Remote No user interaction
Displaying vulnerabilities 1776 - 1800 of 2503 in total