Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 10:13 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

84Investigate

Oracle

CVE-2020-14644

WebLogic Server

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access…

EPSS
94.5%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Apache

CVE-2020-11978

Airflow

Known exploitation is confirmed by CISA KEV. An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated…

EPSS
99.2%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Sonatype

CVE-2020-10199

Nexus, Nexus Repository

Known exploitation is confirmed by CISA KEV. Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

EPSS
99.1%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

SolarWinds

CVE-2020-10148

Orion, Orion Platform

Known exploitation is confirmed by CISA KEV. The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute…

EPSS
92.0%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Opensourcebms, ThinkPHP +1 more

CVE-2019-9082

Open Source Background Management System, ThinkPHP, Zzzphp

Known exploitation is confirmed by CISA KEV. ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

EPSS
97.4%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Atlassian

CVE-2019-3398

Confluence Server, Confluence Server and Data Center

Known exploitation is confirmed by CISA KEV. Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create…

EPSS
96.8%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

D-Link, Dlink

CVE-2019-17621

Dir-818lx Firmware, Dir-822 Firmware, Dir-823 Firmware +12 more

Known exploitation is confirmed by CISA KEV. The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP…

EPSS
89.6%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Citrix

CVE-2019-12989

Netscaler Sd-wan, Sd-wan, SD-WAN and NetScaler

Known exploitation is confirmed by CISA KEV. Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

EPSS
94.1%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Kentico

CVE-2019-10068

Xperience

Known exploitation is confirmed by CISA KEV. An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially…

EPSS
96.3%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

NUUO

CVE-2018-14933

NVRmini Devices, Nvrmini Firmware

Known exploitation is confirmed by CISA KEV. upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

EPSS
94.9%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

MikroTik

CVE-2018-14847

RouterOS

Known exploitation is confirmed by CISA KEV. MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

EPSS
96.1%
CVSS
9.1
Ransomware
Not reported
View evidence
84Investigate

LG

CVE-2018-14839

N1a1 Firmware, N1A1 NAS

Known exploitation is confirmed by CISA KEV. LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters.

EPSS
89.4%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Fortinet

CVE-2018-13382

FortiOS, FortiOS and FortiProxy, Fortiproxy

Known exploitation is confirmed by CISA KEV. An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN…

EPSS
81.7%
CVSS
7.5
Ransomware
Known
View evidence
84Investigate

Dasan, Dasannetworks

CVE-2018-10561

Gigabit Passive Optical Network (GPON) Routers, Gpon Router Firmware

Known exploitation is confirmed by CISA KEV. An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the…

EPSS
93.0%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Hpe, Intel +1 more

CVE-2017-5689

Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability +36 more

Known exploitation is confirmed by CISA KEV. An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining…

EPSS
92.2%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Adobe

CVE-2017-3066

ColdFusion

Known exploitation is confirmed by CISA KEV. Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could…

EPSS
90.6%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Billion, Zyxel

CVE-2017-18368

5200w-t Firmware, P660HN-T1A Routers, P660hn-t1a V1 Firmware +1 more

Known exploitation is confirmed by CISA KEV. The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated…

EPSS
94.5%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Primetek

CVE-2017-1000486

Primefaces, Primefaces Application

Known exploitation is confirmed by CISA KEV. Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

EPSS
94.1%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Microsoft

CVE-2017-0213

Windows, Windows 10 1507, Windows 10 1511 +8 more

Known exploitation is confirmed by CISA KEV. Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607,…

EPSS
84.1%
CVSS
7.3
Ransomware
Known
View evidence
84Investigate

Apache, Canonical +4 more

CVE-2016-8735

7-mode Transition Tool, Agile Engineering Data Management, Agile Plm +16 more

Known exploitation is confirmed by CISA KEV. Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach…

EPSS
90.3%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

NETGEAR

CVE-2016-6277

D6220 Firmware, D6400 Firmware, Multiple Routers +9 more

Known exploitation is confirmed by CISA KEV. NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other…

EPSS
99.8%
CVSS
8.8
Ransomware
Not reported
View evidence
84Investigate

Apache, Redhat

CVE-2016-4437

Aurora, Fuse, Jboss Middleware Text-only Advisories +1 more

Known exploitation is confirmed by CISA KEV. Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified…

EPSS
93.0%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Adobe, Opensuse +2 more

CVE-2016-4117

Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server From Rhui +6 more

Known exploitation is confirmed by CISA KEV. Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.

EPSS
94.4%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Apache, Canonical +6 more

CVE-2016-3427

Cassandra, Debian Linux, E-series Santricity Management Plug-ins +36 more

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

EPSS
92.3%
CVSS
9.8
Ransomware
Not reported
View evidence
84Investigate

Adobe, Opensuse +2 more

CVE-2015-5122

Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Server Eus +6 more

Known exploitation is confirmed by CISA KEV. Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X,…

EPSS
93.7%
CVSS
9.8
Ransomware
Not reported
View evidence