Skip to content
Weekly Signal

Confirmed attacker activity

Exploited Now

Vulnerabilities with confirmed exploitation evidence, ranked by the Cornish Geek Signal.

Updated 20 Aug 2026 · 04:40 UTC

1671Confirmed exploited
1671In CISA KEV
349Linked to ransomware
1671Guidance available
Clear

Exploitation priorities

1671 matching vulnerabilities

85Fix now

Adobe

CVE-2024-34102

Commerce, Commerce and Magento Open Source, Commerce Webhooks +1 more

Known exploitation is confirmed by CISA KEV. Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could…

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apache

CVE-2024-32113

OFBiz

Known exploitation is confirmed by CISA KEV. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the…

EPSS
99.4%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apache

CVE-2024-27348

Hugegraph, HugeGraph-Server

Known exploitation is confirmed by CISA KEV. RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the…

EPSS
99.2%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

JetBrains

CVE-2024-27199

TeamCity

Known exploitation is confirmed by CISA KEV. In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

EPSS
100.0%
CVSS
7.3
Ransomware
Known
View evidence
85Fix now

ConnectWise

CVE-2024-1708

ScreenConnect

Known exploitation is confirmed by CISA KEV. ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

EPSS
87.6%
CVSS
8.4
Ransomware
Known
View evidence
85Fix now

VMware

CVE-2023-34048

vCenter Server

Known exploitation is confirmed by CISA KEV. vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code…

EPSS
99.4%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apache

CVE-2023-33246

RocketMQ

Known exploitation is confirmed by CISA KEV. For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and…

EPSS
96.6%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Zyxel

CVE-2023-28771

Atp100 Firmware, Atp100w Firmware, Atp200 Firmware +17 more

Known exploitation is confirmed by CISA KEV. Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware…

EPSS
99.3%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Apache

CVE-2023-27524

Superset

Known exploitation is confirmed by CISA KEV. Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and…

EPSS
97.4%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Commscope, Ruckus Wireless +1 more

CVE-2023-25717

Multiple Products, Ruckus Smartzone Firmware, Ruckus Wireless Admin +1 more

Known exploitation is confirmed by CISA KEV. Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.

EPSS
98.1%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

D-Link, Dlink

CVE-2023-25280

DIR-820 Router, Dir-820l Firmware

Known exploitation is confirmed by CISA KEV. OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

EPSS
97.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Microsoft

CVE-2023-23397

365 Apps, Office, Office Long Term Servicing Channel +1 more

Known exploitation is confirmed by CISA KEV. Microsoft Outlook Elevation of Privilege Vulnerability

EPSS
97.4%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

VMware

CVE-2023-20887

Aria Operations for Networks

Known exploitation is confirmed by CISA KEV. Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in…

EPSS
98.3%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Cisco, Rockwellautomation

CVE-2023-20198

Allen-bradley Stratix 5200 Firmware, Allen-bradley Stratix 5800 Firmware, Ios Xe +1 more

Known exploitation is confirmed by CISA KEV. Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding…

EPSS
99.6%
CVSS
10.0
Ransomware
Not reported
View evidence
85Fix now

Sophos

CVE-2023-1671

Web Appliance

Known exploitation is confirmed by CISA KEV. A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Cacti

CVE-2022-46169

Cacti

Known exploitation is confirmed by CISA KEV. Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to…

EPSS
99.8%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Control-webpanel, CWP

CVE-2022-44877

Control Web Panel, Webpanel

Known exploitation is confirmed by CISA KEV. login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.

EPSS
100.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Sophos

CVE-2022-3236

Firewall

Known exploitation is confirmed by CISA KEV. A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

EPSS
98.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

ZK Framework, Zkoss

CVE-2022-36537

AuUploader, Zk Framework

Known exploitation is confirmed by CISA KEV. ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

EPSS
95.3%
CVSS
7.5
Ransomware
Known
View evidence
85Fix now

Glpi-project, Teclib

CVE-2022-35914

GLPI

Known exploitation is confirmed by CISA KEV. /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

EPSS
99.7%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Zoho, Zohocorp

CVE-2022-35405

ManageEngine, Manageengine Access Manager Plus, Manageengine Pam360 +1 more

Known exploitation is confirmed by CISA KEV. Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

EPSS
99.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Zyxel

CVE-2022-30525

Atp100 Firmware, Atp100w Firmware, Atp200 Firmware +14 more

Known exploitation is confirmed by CISA KEV. A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG…

EPSS
99.9%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Contec, SolarView

CVE-2022-29303

Compact, Sv-cpt-mc310 Firmware

Known exploitation is confirmed by CISA KEV. SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.

EPSS
98.0%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Atlassian

CVE-2022-26138

Confluence, Questions For Confluence

Known exploitation is confirmed by CISA KEV. The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated…

EPSS
98.2%
CVSS
9.8
Ransomware
Not reported
View evidence
85Fix now

Geosolutionsgroup, OSGeo

CVE-2022-24816

JAI-EXT

Known exploitation is confirmed by CISA KEV. JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution…

EPSS
98.7%
CVSS
10.0
Ransomware
Not reported
View evidence