Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 12:36 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

83Investigate

Cisco

CVE-2020-3161

8831 Firmware, Cisco IP Phones, Ip Phone 7811 Firmware +11 more

Known exploitation is confirmed by CISA KEV. A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting…

EPSS
83.7%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Draytek

CVE-2020-15415

Multiple Vigor Routers, Vigor2960 Firmware, Vigor300b Firmware +1 more

Known exploitation is confirmed by CISA KEV. On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

EPSS
84.6%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Oracle

CVE-2020-14871

Solaris, Solaris and Zettabyte File System (ZFS)

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

EPSS
79.8%
CVSS
10.0
Ransomware
Not reported
View evidence
83Investigate

Opensuse, Roundcube

CVE-2020-12641

Backports Sle, Leap, Roundcube Webmail +1 more

Known exploitation is confirmed by CISA KEV. rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.

EPSS
84.5%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Tenda

CVE-2020-10987

Ac15 Firmware, AC1900 Router AC15 Model

Known exploitation is confirmed by CISA KEV. The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

EPSS
79.8%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Sitecore

CVE-2019-9874

Cms, CMS and Experience Platform (XP), Experience Platform

Known exploitation is confirmed by CISA KEV. Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by…

EPSS
83.9%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Ibm

CVE-2019-4716

Planning Analytics

Known exploitation is confirmed by CISA KEV. IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.…

EPSS
86.4%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

D-Link, Dlink

CVE-2019-20500

DWL-2600AP Access Point, Dwl-2600ap Firmware

Known exploitation is confirmed by CISA KEV. D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.

EPSS
97.1%
CVSS
7.8
Ransomware
Not reported
View evidence
83Investigate

Cisco

CVE-2019-1653

Rv320 Firmware, Rv325 Firmware, Small Business RV320 and RV325 Routers

Known exploitation is confirmed by CISA KEV. A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is…

EPSS
99.9%
CVSS
7.5
Ransomware
Not reported
View evidence
83Investigate

Atlassian

CVE-2019-11581

Jira Server, Jira Server and Data Center

Known exploitation is confirmed by CISA KEV. There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run…

EPSS
84.6%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Mongo-express Project, Mongodb

CVE-2019-10758

mongo-express

Known exploitation is confirmed by CISA KEV. mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

EPSS
84.8%
CVSS
9.9
Ransomware
Not reported
View evidence
83Investigate

Paessler

CVE-2018-19410

Prtg Network Monitor

Known exploitation is confirmed by CISA KEV. PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include'…

EPSS
86.6%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Apache, Netapp +1 more

CVE-2018-11776

Active Iq Unified Manager, Communications Policy Management, Enterprise Manager Base Platform +5 more

Known exploitation is confirmed by CISA KEV. Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results…

EPSS
100.0%
CVSS
8.1
Ransomware
Not reported
View evidence
83Investigate

Microsoft

CVE-2018-0798

Office, Office Compatibility Pack, Word

Known exploitation is confirmed by CISA KEV. Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka…

EPSS
91.0%
CVSS
8.8
Ransomware
Not reported
View evidence
83Investigate

Apache, Cisco +1 more

CVE-2017-9805

Digital Media Manager, Hosted Collaboration Solution, Media Experience Engine +4 more

Known exploitation is confirmed by CISA KEV. The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead…

EPSS
99.4%
CVSS
8.1
Ransomware
Not reported
View evidence
83Investigate

Microsoft

CVE-2017-8464

Windows, Windows 10 1511, Windows 10 1607 +7 more

Known exploitation is confirmed by CISA KEV. Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607,…

EPSS
88.6%
CVSS
8.8
Ransomware
Not reported
View evidence
83Investigate

Embedthis, Oracle

CVE-2017-17562

Goahead, Integrated Lights Out Manager

Known exploitation is confirmed by CISA KEV. Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CGI scripts using…

EPSS
96.3%
CVSS
8.1
Ransomware
Not reported
View evidence
83Investigate

Apache, Canonical +4 more

CVE-2017-12617

Active Iq Unified Manager, Agile Plm, Communications Instant Messaging Server +55 more

Known exploitation is confirmed by CISA KEV. When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default…

EPSS
100.0%
CVSS
8.1
Ransomware
Not reported
View evidence
83Investigate

Telerik

CVE-2017-11317

Ui For Asp.net Ajax, User Interface (UI) for ASP.NET AJAX

Known exploitation is confirmed by CISA KEV. Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute…

EPSS
83.5%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Cisco

CVE-2016-6366

Adaptive Security Appliance (ASA), Adaptive Security Appliance Software, Asa 1000v Cloud Firewall Software +1 more

Known exploitation is confirmed by CISA KEV. Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows…

EPSS
87.6%
CVSS
8.8
Ransomware
Not reported
View evidence
83Investigate

Canonical, Debian +3 more

CVE-2016-3714

Debian Linux, Imagemagick, Leap +3 more

Known exploitation is confirmed by CISA KEV. The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute…

EPSS
97.5%
CVSS
8.4
Ransomware
Not reported
View evidence
83Investigate

Netgear

CVE-2016-10174

D6100 Firmware, D7000 Firmware, D7800 Firmware +26 more

Known exploitation is confirmed by CISA KEV. The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

EPSS
83.5%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

D-Link and TRENDnet, Dlink +1 more

CVE-2015-1187

Dir-626l Firmware, Dir-636l Firmware, Dir-651 Firmware +13 more

Known exploitation is confirmed by CISA KEV. The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

EPSS
82.9%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Adobe, Microsoft +1 more

CVE-2015-0311

Edge, Flash Player, Internet Explorer +2 more

Known exploitation is confirmed by CISA KEV. Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code…

EPSS
85.8%
CVSS
9.8
Ransomware
Not reported
View evidence
83Investigate

Microsoft

CVE-2014-6332

Windows, Windows 7, Windows 8 +7 more

Known exploitation is confirmed by CISA KEV. OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,…

EPSS
95.0%
CVSS
8.8
Ransomware
Not reported
View evidence