0.7%
actively
exploited
exploited
Focus on what’s exploited
Out of 350,184 known CVEs, only 0.7% show real-world exploitation signals.
Data from public sources (including CISA) plus private sensors, enriched with prioritization metadata.
2,501
Total Known exploited
353
Added this week
Search
Results update as you type.
⌘K
Added
Exploitability
Type to search. Filters apply instantly.
| CVE | Severity | Title |
|---|---|---|
| CVE-2020-0683 | 7.8 High |
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation...
Low complexity
No user interaction
|
| CVE-2020-17087 | 7.8 High |
Windows Kernel Local Elevation of Privilege Vulnerability
Low complexity
No user interaction
|
| CVE-2021-33742 | 7.5 High |
Windows MSHTML Platform Remote Code Execution Vulnerability
Remote
|
| CVE-2021-31199 | 5.2 Medium |
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
Low complexity
No user interaction
|
| CVE-2021-33771 | 7.8 High |
Windows Kernel Elevation of Privilege Vulnerability
Low complexity
No user interaction
|
| CVE-2021-31956 | 7.8 High |
Windows NTFS Elevation of Privilege Vulnerability
Low complexity
No user interaction
|
| CVE-2021-31201 | 5.2 Medium |
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
Low complexity
No user interaction
|
| CVE-2021-31979 | 7.8 High |
Windows Kernel Elevation of Privilege Vulnerability
Low complexity
No user interaction
|
| CVE-2020-0938 | 7.8 High |
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a...
Low complexity
|
| CVE-2020-17144 | 8.4 High |
Microsoft Exchange Remote Code Execution Vulnerability
Remote
Low complexity
|
| CVE-2020-0986 | 7.8 High |
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of...
Low complexity
No user interaction
|
| CVE-2020-1020 | 8.8 High |
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a...
Remote
Low complexity
|
| CVE-2021-38645 | 7.8 High |
Open Management Infrastructure Elevation of Privilege Vulnerability
Low complexity
No user interaction
|
| CVE-2021-34523 | 9.0 Critical |
Microsoft Exchange Server Elevation of Privilege Vulnerability
Malware
Low complexity
No user interaction
|
| CVE-2017-7269 | 9.8 Critical |
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server...
Remote
Low complexity
No user interaction
|
| CVE-2021-36948 | 7.8 High |
Windows Update Medic Service Elevation of Privilege Vulnerability
Low complexity
No user interaction
|
| CVE-2021-38649 | 7.0 High |
Open Management Infrastructure Elevation of Privilege Vulnerability
No user interaction
|
| CVE-2020-0688 | 8.8 High |
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2017-0143 | 8.8 High |
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2;...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2016-7255 | 7.8 High |
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold...
Low complexity
|
| CVE-2019-0708 | 9.8 Critical |
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2019-5544 | 9.8 Critical |
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the...
Malware
Remote
Low complexity
No user interaction
|
| CVE-2019-16759 | 9.8 Critical |
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
Remote
Low complexity
No user interaction
|
| CVE-2020-5847 | 9.8 Critical |
Unraid through 6.8.0 allows Remote Code Execution.
Remote
Low complexity
No user interaction
|
| CVE-2020-5849 | 7.5 High |
Unraid 6.8.0 allows authentication bypass.
Remote
Low complexity
No user interaction
|
Displaying vulnerabilities 2101 - 2125 of 2501 in total