Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 16:12 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

81Investigate

Ivanti

CVE-2026-1603

Endpoint Manager, Endpoint Manager (EPM)

Known exploitation is confirmed by CISA KEV. An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

EPSS
80.6%
CVSS
7.5
Ransomware
Not reported
View evidence
81Investigate

3ds, Dassault Systèmes

CVE-2025-6204

DELMIA Apriso

Known exploitation is confirmed by CISA KEV. An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.

EPSS
76.1%
CVSS
8.0
Ransomware
Not reported
View evidence
81Investigate

3ds, Dassault Systèmes

CVE-2025-6205

DELMIA Apriso

Known exploitation is confirmed by CISA KEV. A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

EPSS
71.1%
CVSS
9.1
Ransomware
Not reported
View evidence
81Investigate

Fortinet, Siemens

CVE-2025-59718

FortiOS, Fortiproxy, Fortiswitchmanager +2 more

Known exploitation is confirmed by CISA KEV. A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through…

EPSS
63.4%
CVSS
9.8
Ransomware
Not reported
View evidence
81Investigate

Geoserver, OSGeo

CVE-2025-58360

GeoServer

Known exploitation is confirmed by CISA KEV. GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified.…

EPSS
64.9%
CVSS
9.8
Ransomware
Not reported
View evidence
81Investigate

SysAid

CVE-2025-2776

Sysaid, SysAid On-Prem

Known exploitation is confirmed by CISA KEV. SysAid On-Prem versions

EPSS
64.4%
CVSS
9.8
Ransomware
Not reported
View evidence
81Investigate

D-Link, Dlink

CVE-2025-29635

DIR-823X, Dir-823x Firmware

Known exploitation is confirmed by CISA KEV. A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function,…

EPSS
89.6%
CVSS
7.2
Ransomware
Not reported
View evidence
81Investigate

Cisco

CVE-2025-20337

Identity Services Engine, Identity Services Engine Passive Identity Connector

Known exploitation is confirmed by CISA KEV. A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does…

EPSS
66.3%
CVSS
10.0
Ransomware
Not reported
View evidence
81Investigate

Edimax

CVE-2025-1316

Ic-7100 Firmware, IC-7100 IP Camera

Known exploitation is confirmed by CISA KEV. Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device

EPSS
73.2%
CVSS
9.3
Ransomware
Not reported
View evidence
81Investigate

Ivanti

CVE-2024-8190

Cloud Services Appliance

Known exploitation is confirmed by CISA KEV. An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level…

EPSS
88.5%
CVSS
7.2
Ransomware
Not reported
View evidence
81Investigate

AMI, Netapp

CVE-2024-54085

H300s Firmware, H410c Firmware, H410s Firmware +8 more

Known exploitation is confirmed by CISA KEV. AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of…

EPSS
60.8%
CVSS
10.0
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2024-38112

Windows, Windows 10 1507, Windows 10 1607 +12 more

Known exploitation is confirmed by CISA KEV. Windows MSHTML Platform Spoofing Vulnerability

EPSS
84.2%
CVSS
7.5
Ransomware
Not reported
View evidence
81Investigate

Fortinet

CVE-2024-23113

FortiOS, Fortipam, Fortiproxy +2 more

Known exploitation is confirmed by CISA KEV. A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions…

EPSS
61.7%
CVSS
9.8
Ransomware
Not reported
View evidence
81Investigate

Canonical, Debian +5 more

CVE-2023-4911

Bootstrap Os, Codeready Linux Builder, Codeready Linux Builder Eus +37 more

Known exploitation is confirmed by CISA KEV. A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment…

EPSS
81.4%
CVSS
7.8
Ransomware
Not reported
View evidence
81Investigate

QNAP

CVE-2023-47565

Qvr Firmware, VioStor NVR

Known exploitation is confirmed by CISA KEV. An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a…

EPSS
73.3%
CVSS
8.8
Ransomware
Not reported
View evidence
81Investigate

MinIO

CVE-2023-28432

MinIO

Known exploitation is confirmed by CISA KEV. Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All…

EPSS
84.0%
CVSS
7.5
Ransomware
Not reported
View evidence
81Investigate

Cisco

CVE-2023-20273

Cisco IOS XE Web UI, Ios Xe

Known exploitation is confirmed by CISA KEV. A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient…

EPSS
89.6%
CVSS
7.2
Ransomware
Not reported
View evidence
81Investigate

Microsoft

CVE-2022-44698

Defender, Windows 10 1607, Windows 10 1809 +8 more

Known exploitation is confirmed by CISA KEV. Windows SmartScreen Security Feature Bypass Vulnerability

EPSS
76.3%
CVSS
5.4
Ransomware
Known
View evidence
81Investigate

Oracle

CVE-2022-21445

ADF Faces, Application Development Framework

Known exploitation is confirmed by CISA KEV. Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with…

EPSS
62.5%
CVSS
9.8
Ransomware
Not reported
View evidence
81Investigate

Grafana, Grafana Labs

CVE-2021-43798

Grafana

Known exploitation is confirmed by CISA KEV. Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path…

EPSS
88.8%
CVSS
7.5
Ransomware
Not reported
View evidence
81Investigate

D-Link, Dlink

CVE-2021-40655

DIR-605 Router, Dir-605l Firmware

Known exploitation is confirmed by CISA KEV. An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

EPSS
86.7%
CVSS
7.5
Ransomware
Not reported
View evidence
81Investigate

Delta Electronics, Deltaww

CVE-2021-38406

Dopsoft, DOPSoft 2

Known exploitation is confirmed by CISA KEV. Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this…

EPSS
77.9%
CVSS
7.8
Ransomware
Not reported
View evidence
81Investigate

Brocade, Linux +1 more

CVE-2021-22555

Aff 500f Firmware, Aff A250 Firmware, Aff A400 Firmware +19 more

Known exploitation is confirmed by CISA KEV. A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

EPSS
78.7%
CVSS
7.8
Ransomware
Not reported
View evidence
81Investigate

Adminer, Debian

CVE-2021-21311

Adminer, Debian Linux

Known exploitation is confirmed by CISA KEV. Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all…

EPSS
90.5%
CVSS
7.2
Ransomware
Not reported
View evidence
81Investigate

Ivanti

CVE-2020-8243

Connect Secure, Policy Secure, Pulse Connect Secure

Known exploitation is confirmed by CISA KEV. A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.

EPSS
90.8%
CVSS
7.2
Ransomware
Not reported
View evidence