Live data
Exploited vulnerabilities, page 35
Entries 1,701 to 1,739
1,739 in total| Product | What an attacker gains | Concerns | Severity | Added |
|---|---|---|---|---|
ThinkPHP noneCmsCVE-2018-20062 | Code execution | Business | 9.8 | |
DotNetNuke (DNN)CVE-2018-18325 | Vulnerability | Business | 7.5 | |
Adobe ColdFusionCVE-2018-15961 | File access | Business | 9.8 | |
DotNetNuke (DNN)CVE-2018-15811 | Vulnerability | Business | 7.5 | |
Tenda AC7, AC9, and AC10 RoutersCVE-2018-14558 | Code execution | Home network | 9.8 | |
Fortinet FortiOSCVE-2018-13379 | File accessused by ransomware | Business | 9.8 | |
Apache StrutsCVE-2018-11776 | Code execution | Business | 8.1 | |
Microsoft OfficeCVE-2018-0802 | Memory corruptionused by ransomware | Everyone | 7.8 | |
Microsoft OfficeCVE-2018-0798 | Memory corruption | Everyone | 8.8 | |
Cisco Adaptive Security Appliance (ASA)CVE-2018-0296 | Denial of service | Business | 7.5 | |
Cisco IOS and IOS XECVE-2018-0171 | Code execution | Everyone | 9.8 | |
DotNetNuke (DNN)CVE-2017-9822 | Code executionused by ransomware | Business | 8.8 | |
Apache StrutsCVE-2017-9805 | Code execution | Business | 8.1 | |
Progress ASP.NET AJAX and SitefinityCVE-2017-9248 | Cross-site scripting | Business | 9.8 | |
Microsoft .NET FrameworkCVE-2017-8759 | Code execution | Business | 7.8 | |
Microsoft Internet Information Services (IIS)CVE-2017-7269 | Memory corruption | Business | 9.8 | |
Symantec Messaging GatewayCVE-2017-6327 | Code execution | Business | 8.8 | |
Apache StrutsCVE-2017-5638 | Code executionused by ransomware | Business | 9.8 | |
Roundcube WebmailCVE-2017-16651 | Improper access control | Business | 7.8 | |
Microsoft OfficeCVE-2017-11882 | Memory corruptionused by ransomware | Everyone | 7.8 | |
Microsoft OfficeCVE-2017-11774 | Security bypass | Everyone | 7.8 | |
Microsoft Office and WordPadCVE-2017-0199 | Code executionused by ransomware | Everyone | 7.8 | |
Microsoft WindowsCVE-2017-0143 | Code executionused by ransomware | Everyone | 8.8 | |
SAP NetWeaverCVE-2016-9563 | XML external entity | Business | 6.5 | |
Microsoft Win32kCVE-2016-7255 | Privilege escalationused by ransomware | Everyone | 7.8 | |
Apache ShiroCVE-2016-4437 | Code execution | Business | 9.8 | |
SAP NetWeaverCVE-2016-3976 | File access | Business | 7.5 | |
ImageMagickCVE-2016-3718 | Server-side request forgery | Business | 5.5 | |
ImageMagickCVE-2016-3715 | File access | Business | 5.5 | |
SolarWinds Virtualization ManagerCVE-2016-3643 | Privilege escalation | Business | 7.8 | |
Microsoft OfficeCVE-2016-3235 | Code execution | Everyone | 7.8 | |
Microsoft WindowsCVE-2016-0185 | Code execution | Everyone | 7.8 | |
Microsoft Win32kCVE-2016-0167 | Privilege escalationused by ransomware | Everyone | 7.8 | |
Oracle WebLogic ServerCVE-2015-4852 | Code execution | Business | 9.8 | |
Microsoft OfficeCVE-2015-1641 | Memory corruption | Everyone | 7.8 | |
Microsoft WindowsCVE-2014-1812 | Privilege escalationused by ransomware | Everyone | 8.8 | |
Oracle Fusion MiddlewareCVE-2012-3152 | Vulnerability | Business | 9.1 | |
Microsoft MSCOMCTL.OCXCVE-2012-0158 | Code executionused by ransomware | Business | 8.8 | |
SAP NetWeaverCVE-2010-5326 | Code execution | Business | 10.0 |
Source: CISA Known Exploited Vulnerabilities catalogsource updated Oct 8, 2026, 20:09 UTC
Severity (CVSS): NIST NVD