Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 15:00 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

82Investigate

Vmware

CVE-2018-6961

Nsx Sd-wan By Velocloud, SD-WAN Edge

Known exploitation is confirmed by CISA KEV. VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled…

EPSS
86.3%
CVSS
8.1
Ransomware
Not reported
View evidence
82Investigate

Debian, Google +1 more

CVE-2018-17463

Chrome, Chromium V8, Debian Linux +3 more

Known exploitation is confirmed by CISA KEV. Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

EPSS
84.6%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Red Hat, Redhat

CVE-2018-14667

Enterprise Linux, JBoss RichFaces Framework, Richfaces

Known exploitation is confirmed by CISA KEV. The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of…

EPSS
74.2%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Progress, Telerik

CVE-2017-9248

ASP.NET AJAX and Sitefinity, Sitefinity, Ui For Asp.net Ajax

Known exploitation is confirmed by CISA KEV. Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to…

EPSS
75.1%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Artifex, Debian +1 more

CVE-2017-8291

Debian Linux, Enterprise Linux Desktop, Enterprise Linux Eus +5 more

Known exploitation is confirmed by CISA KEV. Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs…

EPSS
96.1%
CVSS
7.8
Ransomware
Not reported
View evidence
82Investigate

Citrix

CVE-2017-6316

Netscaler Sd-wan, NetScaler SD-WAN Enterprise, CloudBridge Virtual WAN +1 more

Known exploitation is confirmed by CISA KEV. Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name…

EPSS
72.6%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Netgear

CVE-2017-5521

Ac1450 Firmware, D6220 Firmware, D6300 Firmware +11 more

Known exploitation is confirmed by CISA KEV. An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to…

EPSS
89.4%
CVSS
8.1
Ransomware
Not reported
View evidence
82Investigate

Oracle

CVE-2017-3506

Weblogic Server

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated…

EPSS
96.3%
CVSS
7.4
Ransomware
Not reported
View evidence
82Investigate

Sap

CVE-2017-12637

Netweaver, Netweaver Application Server Java

Known exploitation is confirmed by CISA KEV. Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the…

EPSS
95.1%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2016-7201

Edge

Known exploitation is confirmed by CISA KEV. The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory…

EPSS
79.7%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2016-7200

Edge

Known exploitation is confirmed by CISA KEV. The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory…

EPSS
82.5%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Sap

CVE-2016-2386

Netweaver, Netweaver Application Server Java

Known exploitation is confirmed by CISA KEV. SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

EPSS
71.1%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Debian, Opensuse +4 more

CVE-2016-0752

Debian Linux, Leap, Linux Enterprise Module For Containers +4 more

Known exploitation is confirmed by CISA KEV. Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by…

EPSS
95.5%
CVSS
7.5
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2016-0151

Client-Server Run-time Subsystem (CSRSS), Windows 10 1507, Windows 10 1511 +3 more

Known exploitation is confirmed by CISA KEV. The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to…

EPSS
63.2%
CVSS
7.8
Ransomware
Known
View evidence
82Investigate

Adobe, Opensuse +2 more

CVE-2015-7645

Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server +7 more

Known exploitation is confirmed by CISA KEV. Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF…

EPSS
68.4%
CVSS
7.8
Ransomware
Known
View evidence
82Investigate

Adobe, Novell +2 more

CVE-2015-3043

Enterprise Linux Desktop, Enterprise Linux Eus, Enterprise Linux Server +8 more

Known exploitation is confirmed by CISA KEV. Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of…

EPSS
74.4%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2015-2426

Windows, Windows 10, Windows 7 +7 more

Known exploitation is confirmed by CISA KEV. Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server…

EPSS
86.7%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2015-1641

Office, Office Compatibility Pack, Office Web Apps +3 more

Known exploitation is confirmed by CISA KEV. Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010…

EPSS
92.9%
CVSS
7.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2014-4113

Win32k, Windows 7, Windows 8 +7 more

Known exploitation is confirmed by CISA KEV. win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold…

EPSS
87.0%
CVSS
7.8
Ransomware
Not reported
View evidence
82Investigate

Elastic

CVE-2014-3120

Elasticsearch

Known exploitation is confirmed by CISA KEV. The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates…

EPSS
88.6%
CVSS
8.1
Ransomware
Not reported
View evidence
82Investigate

Indusoft

CVE-2014-0780

Web Studio

Known exploitation is confirmed by CISA KEV. Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web…

EPSS
74.5%
CVSS
9.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2014-0322

Internet Explorer

Known exploitation is confirmed by CISA KEV. Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as…

EPSS
85.2%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2013-3893

Internet Explorer

Known exploitation is confirmed by CISA KEV. Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an…

EPSS
85.9%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Microsoft

CVE-2013-1347

Internet Explorer

Known exploitation is confirmed by CISA KEV. Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is…

EPSS
77.9%
CVSS
8.8
Ransomware
Not reported
View evidence
82Investigate

Adobe, Opensuse +2 more

CVE-2013-0640

Acrobat, Acrobat Reader, Enterprise Linux Desktop +7 more

Known exploitation is confirmed by CISA KEV. Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted…

EPSS
87.0%
CVSS
7.8
Ransomware
Not reported
View evidence