Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 06:50 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

85Fix now

Ivanti, Pulsesecure

CVE-2019-11539

Connect Secure, Policy Secure, Pulse Connect Secure and Pulse Policy Secure +1 more

Known exploitation is confirmed by CISA KEV. In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX…

EPSS
98.5%
CVSS
7.2
Ransomware
Known
View evidence
85Fix now

Canonical, Debian +1 more

CVE-2019-10149

Debian Linux, Exim, Mail Transfer Agent (MTA) +1 more

Known exploitation is confirmed by CISA KEV. A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Jenkins, Redhat

CVE-2019-1003030

Matrix Project Plugin, Openshift Container Platform, Pipeline: Groovy

Known exploitation is confirmed by CISA KEV. A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master…

EPSS
96.9%
CVSS
9.9
Ransomware
Not reported
View evidence
85Fix now

Adobe, Redhat

CVE-2018-4878

Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Workstation +1 more

Known exploitation is confirmed by CISA KEV. A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A…

EPSS
89.5%
CVSS
7.8
Ransomware
Known
View evidence
85Fix now

Oracle

CVE-2018-2628

WebLogic Server

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker…

EPSS
99.4%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

5none, ThinkPHP

CVE-2018-20062

noneCms

Known exploitation is confirmed by CISA KEV. An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.

EPSS
99.5%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Adobe

CVE-2018-15961

ColdFusion

Known exploitation is confirmed by CISA KEV. Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Jenkins, Redhat

CVE-2018-1000861

Jenkins, Jenkins Stapler Web Framework, Openshift Container Platform

Known exploitation is confirmed by CISA KEV. A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects…

EPSS
98.3%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Microsoft

CVE-2018-0802

Office, Office Compatibility Pack, Word

Known exploitation is confirmed by CISA KEV. Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka…

EPSS
87.4%
CVSS
7.8
Ransomware
Known
View evidence
85Fix now

Cisco

CVE-2018-0171

IOS, IOS and IOS XE

Known exploitation is confirmed by CISA KEV. A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in…

EPSS
99.5%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Oracle, PHPUnit +1 more

CVE-2017-9841

Communications Diameter Signaling Router, PHPUnit

Known exploitation is confirmed by CISA KEV. Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apache

CVE-2017-9791

Struts, Struts 1

Known exploitation is confirmed by CISA KEV. The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.

EPSS
98.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Hikvision

CVE-2017-7921

Ds-2cd2032-i Firmware, Ds-2cd2112-i Firmware, Ds-2cd2132-i Firmware +56 more

Known exploitation is confirmed by CISA KEV. An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to…

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Microsoft

CVE-2017-7269

Internet Information Services, Internet Information Services (IIS)

Known exploitation is confirmed by CISA KEV. Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long…

EPSS
99.8%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Cisco

CVE-2017-3881

IOS, IOS and IOS XE, Ios Xe

Known exploitation is confirmed by CISA KEV. A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected…

EPSS
99.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Palo Alto Networks, Paloaltonetworks

CVE-2017-15944

PAN-OS

Known exploitation is confirmed by CISA KEV. Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

EPSS
98.3%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Jenkins, Oracle

CVE-2017-1000353

Communications Cloud Native Core Automated Test Suite, Jenkins

Known exploitation is confirmed by CISA KEV. Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized…

EPSS
99.7%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apache

CVE-2016-3088

ActiveMQ

Known exploitation is confirmed by CISA KEV. The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

EPSS
98.5%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

NETGEAR

CVE-2016-1555

Wireless Access Point (WAP) Devices, Wn604 Firmware, Wn802tv2 Firmware +5 more

Known exploitation is confirmed by CISA KEV. (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute arbitrary…

EPSS
98.3%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Joomla!, PHP +2 more

CVE-2016-10033

Joomla!, PHPMailer, Wordpress

Known exploitation is confirmed by CISA KEV. The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash…

EPSS
99.7%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Microsoft

CVE-2016-0189

Internet Explorer, Jscript, Vbscript

Known exploitation is confirmed by CISA KEV. The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause…

EPSS
93.7%
CVSS
7.5
Ransomware
Known
View evidence
85Fix now

IBM

CVE-2015-7450

Sterling B2b Integrator, Sterling Integrator, Tivoli Common Reporting +5 more

Known exploitation is confirmed by CISA KEV. Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the…

EPSS
97.7%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Adobe, Opensuse +2 more

CVE-2015-5119

Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server +8 more

Known exploitation is confirmed by CISA KEV. Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468…

EPSS
99.3%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Adobe, Hp +3 more

CVE-2015-3113

Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server +12 more

Known exploitation is confirmed by CISA KEV. Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code…

EPSS
99.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Microsoft

CVE-2015-1635

HTTP.sys, Windows 7, Windows 8 +3 more

Known exploitation is confirmed by CISA KEV. HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP…

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence