Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 14:25 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

82Investigate

Fedoraproject, Grafana +1 more

CVE-2021-39226

Fedora, Grafana

Known exploitation is confirmed by CISA KEV. Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key,…

EPSS
99.9%
CVSS
7.3
Ransomware
Not reported
View evidence
82Investigate

Citrix

CVE-2021-22941

ShareFile, Sharefile Storagezones Controller

Known exploitation is confirmed by CISA KEV. Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

EPSS
53.6%
CVSS
9.8
Ransomware
Known
View evidence
82Investigate

Omnissa, Vmware

CVE-2021-22054

Workspace One UEM, Workspace One Uem Console

Known exploitation is confirmed by CISA KEV. VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious…

EPSS
97.4%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Apache, Npm package +1 more

CVE-2021-21315

Cordova, System Information Library for Node.JS, Systeminformation

Known exploitation is confirmed by CISA KEV. The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a…

EPSS
90.7%
CVSS
7.8
Ransomware
Not reported
View evidence
82Investigate

Adobe

CVE-2021-21017

Acrobat, Acrobat and Reader, Acrobat Dc +2 more

Known exploitation is confirmed by CISA KEV. Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve…

EPSS
86.3%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Ivanti

CVE-2020-8260

Connect Secure, Pulse Connect Secure

Known exploitation is confirmed by CISA KEV. A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

EPSS
96.5%
CVSS
7.2
Ransomware
Not reported
View evidence
82Investigate

Debian, Fedoraproject +2 more

CVE-2020-6418

Chrome, Chromium V8, Debian Linux +4 more

Known exploitation is confirmed by CISA KEV. Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS
78.8%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Unraid

CVE-2020-5849

Unraid

Known exploitation is confirmed by CISA KEV. Unraid 6.8.0 allows authentication bypass.

EPSS
93.2%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Vmware, VMware Tanzu

CVE-2020-5410

Spring Cloud Config, Spring Cloud Configuration (Config) Server

Known exploitation is confirmed by CISA KEV. Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or…

EPSS
95.6%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Ibm

CVE-2020-4427

Data Risk Manager

Known exploitation is confirmed by CISA KEV. IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request,…

EPSS
70.0%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

D-Link, Dlink

CVE-2020-25078

DCS-2530L and DCS-2670L Devices, Dcs-2530l Firmware, Dcs-2670l Firmware +7 more

Known exploitation is confirmed by CISA KEV. An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.

EPSS
97.7%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2020-1147

.net Core, .net Framework, .NET Framework +6 more

Known exploitation is confirmed by CISA KEV. A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server,…

EPSS
94.3%
CVSS
7.8
Ransomware
Not reported
View evidence
82Investigate

Apache

CVE-2020-17519

Flink

Known exploitation is confirmed by CISA KEV. A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface…

EPSS
97.9%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Oracle

CVE-2020-14883

Weblogic Server

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker…

EPSS
97.9%
CVSS
7.2
Ransomware
Not reported
View evidence
82Investigate

Oracle

CVE-2020-14864

Business Intelligence, Intelligence Enterprise Edition

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with…

EPSS
97.2%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Awesomemotive, Wordpress

CVE-2020-11738

Duplicator, Snap Creek Duplicator Plugin

Known exploitation is confirmed by CISA KEV. The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.

EPSS
97.8%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Golang, Microsoft

CVE-2020-0601

Go, Windows, Windows 10 1507 +11 more

Known exploitation is confirmed by CISA KEV. A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable,…

EPSS
89.4%
CVSS
8.1
Ransomware
Not reported
View evidence
82Investigate

Sonatype

CVE-2019-7238

Nexus Repository Manager

Known exploitation is confirmed by CISA KEV. Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

EPSS
76.5%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Drupal

CVE-2019-6340

Core, Drupal

Known exploitation is confirmed by CISA KEV. Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases.…

EPSS
92.0%
CVSS
8.1
Ransomware
Not reported
View evidence
82Investigate

Debian, Fedoraproject +4 more

CVE-2019-5418

Cloudforms, Debian Linux, Fedora +4 more

Known exploitation is confirmed by CISA KEV. There is a File Content Disclosure vulnerability in Action View

EPSS
98.5%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Tvt

CVE-2019-20085

NVMS-1000, Nvms-1000 Firmware

Known exploitation is confirmed by CISA KEV. TVT NVMS-1000 devices allow GET /.. Directory Traversal

EPSS
96.1%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Cisco

CVE-2019-1652

Rv320 Firmware, Rv325 Firmware, Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers

Known exploitation is confirmed by CISA KEV. A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device…

EPSS
95.9%
CVSS
7.2
Ransomware
Not reported
View evidence
82Investigate

Apache, Oracle

CVE-2019-17558

Primavera Unifier, Solr

Known exploitation is confirmed by CISA KEV. Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or…

EPSS
98.6%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Jenkins, Redhat

CVE-2019-1003029

Openshift Container Platform, Script Security, Script Security Plugin

Known exploitation is confirmed by CISA KEV. A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to execute arbitrary code on the Jenkins master JVM.

EPSS
73.9%
CVSS
9.9
Ransomware
Not reported
View evidence
82Investigate

Schneider-electric

CVE-2018-7841

U.motion Builder

Known exploitation is confirmed by CISA KEV. A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.

EPSS
72.7%
CVSS
9.8
Ransomware
Not reported
View evidence