0.7%
actively
exploited
exploited
Focus on what’s exploited
Out of 350,187 known CVEs, only 0.7% show real-world exploitation signals.
Data from public sources (including CISA) plus private sensors, enriched with prioritization metadata.
2,503
Total Known exploited
426
Added this week
Search
Results update as you type.
⌘K
Added
Exploitability
Type to search. Filters apply instantly.
| CVE | Severity | Title |
|---|---|---|
| CVE-2018-0147 | 9.8 Critical |
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an...
Remote
Low complexity
No user interaction
|
| CVE-2016-4171 | 9.8 Critical |
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as...
Remote
Low complexity
No user interaction
|
| CVE-2016-1555 | 9.8 Critical |
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and...
Remote
Low complexity
No user interaction
|
| CVE-2016-11021 | 7.2 High |
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
Remote
Low complexity
No user interaction
|
| CVE-2016-10174 | 9.8 Critical |
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This...
Remote
Low complexity
No user interaction
|
| CVE-2016-0752 | 7.5 High |
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x...
Remote
Low complexity
No user interaction
|
| CVE-2015-4068 | 9.1 Critical |
Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of...
Remote
Low complexity
No user interaction
|
| CVE-2015-3035 | 7.5 High |
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with...
Remote
Low complexity
No user interaction
|
| CVE-2015-1427 | 9.8 Critical |
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism...
Remote
Low complexity
No user interaction
|
| CVE-2015-1187 | 9.8 Critical |
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
Remote
Low complexity
No user interaction
|
| CVE-2015-0666 | 7.5 High |
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers...
Remote
Low complexity
No user interaction
|
| CVE-2014-6332 | 8.8 High |
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows...
Remote
Low complexity
|
| CVE-2014-6324 | 8.8 High |
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7...
Remote
Low complexity
No user interaction
|
| CVE-2014-6287 | 9.8 Critical |
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to...
Remote
Low complexity
No user interaction
|
| CVE-2014-3120 | 8.1 High |
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL...
Remote
Low complexity
No user interaction
|
| CVE-2014-0130 | 7.5 High |
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before...
Remote
Low complexity
No user interaction
|
| CVE-2013-5223 | 5.4 Medium |
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web...
Remote
Low complexity
|
| CVE-2013-4810 | 9.8 Critical |
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote...
Remote
Low complexity
No user interaction
|
| CVE-2013-2251 | 9.8 Critical |
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2)...
Remote
Low complexity
No user interaction
|
| CVE-2012-1823 | 9.8 Critical |
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query...
Remote
Low complexity
No user interaction
|
| CVE-2010-4345 | 7.8 High |
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate...
Low complexity
No user interaction
|
| CVE-2010-4344 | 9.8 Critical |
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an...
Remote
Low complexity
No user interaction
|
| CVE-2010-3035 | 7.5 High |
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers...
Remote
Low complexity
No user interaction
|
| CVE-2010-2861 | 9.8 Critical |
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2009-2055 | 5.9 Medium |
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid...
Remote
No user interaction
|
Displaying vulnerabilities 1776 - 1800 of 2503 in total