0.7%
actively
exploited
exploited
Focus on what’s exploited
Out of 350,184 known CVEs, only 0.7% show real-world exploitation signals.
Data from public sources (including CISA) plus private sensors, enriched with prioritization metadata.
2,501
Total Known exploited
352
Added this week
Search
Results update as you type.
⌘K
Added
Exploitability
Type to search. Filters apply instantly.
| CVE | Severity | Title |
|---|---|---|
| CVE-2014-1776 | 9.8 Critical |
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of...
Remote
Low complexity
No user interaction
|
| CVE-2014-6271 | 9.8 Critical |
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to...
Remote
Low complexity
No user interaction
|
| CVE-2014-7169 | 9.8 Critical |
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables,...
Remote
Low complexity
No user interaction
|
| CVE-2021-35247 | 4.3 Medium |
Improper Input Validation Vulnerability in Serv-U
Remote
Low complexity
|
| CVE-2018-8453 | 7.8 High |
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k...
Malware
Low complexity
|
| CVE-2006-1547 | 7.5 High |
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a...
Remote
Low complexity
No user interaction
|
| CVE-2012-0391 | 9.8 Critical |
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling...
Remote
Low complexity
No user interaction
|
| CVE-2020-13927 | 9.8 Critical |
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to...
Remote
Low complexity
No user interaction
|
| CVE-2021-32648 | 8.2 High |
Account Takeover in Octobercms
Remote
Low complexity
No user interaction
|
| CVE-2021-25296 | 8.8 High |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote
Low complexity
No user interaction
|
| CVE-2021-25297 | 8.8 High |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote
Low complexity
No user interaction
|
| CVE-2021-25298 | 8.8 High |
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...
Remote
Low complexity
No user interaction
|
| CVE-2021-40870 | 9.8 Critical |
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which...
Remote
Low complexity
No user interaction
|
| CVE-2021-33766 | 7.3 High |
Microsoft Exchange Server Information Disclosure Vulnerability
Remote
Low complexity
No user interaction
|
| CVE-2021-21975 | 7.5 High |
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2021-21315 | 7.1 High |
Command Injection Vulnerability
Low complexity
No user interaction
|
| CVE-2021-22991 | 9.8 Critical |
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3,...
Remote
Low complexity
No user interaction
|
| CVE-2020-14864 | 7.5 High |
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported...
Remote
Low complexity
No user interaction
|
| CVE-2020-13671 | 8.8 High |
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension...
Remote
Low complexity
No user interaction
|
| CVE-2020-11978 | 8.8 High |
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example...
Remote
Low complexity
No user interaction
|
| CVE-2022-21894 | 4.4 Medium |
Secure Boot Security Feature Bypass Vulnerability
Low complexity
No user interaction
|
| CVE-2019-1458 | 7.8 High |
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k...
Malware
Low complexity
No user interaction
|
| CVE-2013-3900 | 5.5 Medium |
WinVerifyTrust Signature Validation Vulnerability
Low complexity
|
| CVE-2019-2725 | 7.5 High |
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2019-9670 | 9.8 Critical |
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as...
Remote
Low complexity
No user interaction
|
Displaying vulnerabilities 2001 - 2025 of 2501 in total