Obsidian Ridge

This week's burn-down

Nothing new this week.

10 fixes from the first two groups are still open. They're below, newest first.

Start here

What to patch first.

180 of these vulnerabilities are actively used in ransomware attacks. Start with these — they're the ones criminals are exploiting right now.

  • Patch first180used in ransomware
  • Patch second193critical, or high-severity on internet-facing gear
  • Patch third417high-severity, or on internet-facing gear
  • Patch fourth55everything else on the list

Every entry here is on CISA's Known Exploited Vulnerabilities list, and CISA's current directive, BOD 26-04, gives federal agencies 3 or 14 days to fix a listed vulnerability.

Treat all four groups as due inside that window and work through them in this order; a later place in the order is not permission to wait.

The order comes from CVSS severity and our guess at internet exposure from the kind of product. Neither is how CISA sets its deadlines: the directive looks at:

  • Whether your system is actually reachable from the internet
  • Whether the attack can be automated
  • How much control it gives an attacker

Want just the ones that hit your gear? Check your stack to pick your vendors and see what's being exploited right now.

Insurance readiness

Your insurer will ask if this is patched.

Unpatched entries on CISA's Known Exploited Vulnerabilities list are exactly what cyber-insurance carrier questionnaires probe for, and knowing which controls they check is how you keep a renewal from stalling.

Get the free carrier questionnaire →

Microsoft updates

One Windows Update run clears all of these.

Windows updates are cumulative: the newest one includes every fix that came before it. Run Windows Update on your machines and everything below is covered. The KB numbers are the receipts, not a to-do list.

  • KB5053618covered 7 actively-exploited CVEs
  • KB5053594covered 7 actively-exploited CVEs
  • KB5053886covered 7 actively-exploited CVEs
  • KB5053887covered 7 actively-exploited CVEs
  • KB5053596covered 6 actively-exploited CVEs
  • KB5053603covered 6 actively-exploited CVEs
  • KB5053638covered 6 actively-exploited CVEs
  • KB5053606covered 6 actively-exploited CVEs
  • KB5053602covered 6 actively-exploited CVEs
  • KB5053598covered 6 actively-exploited CVEs

Known exploited vulnerabilities

What's being actively exploited.

CISA's Known Exploited Vulnerabilities (KEV) catalog is the U.S. government's list of vulnerabilities that have been exploited in the wild. This page tracks the entries that affect software small businesses run, refreshed daily, with what each one affects and what to do about it in plain English. It is not every CVE, only the ones used in real attacks.

Updated 10 hours ago · 845 SMB-relevant entries · Sources: cisagov/kev-data + VulnCheck KEV

Breadth

Exploited in the wild, not yet on CISA's list.

VulnCheck tracks 553 additional SMB-relevant CVEs being actively exploited beyond CISA's KEV catalog. 51 are flagged as used in ransomware campaigns. The list below covers the same vendors as everything else on this page: Microsoft, Apple, Adobe, Cisco, Fortinet, SonicWall, Ivanti, Palo Alto, Google, and Ubiquiti.

  • CVE-2025-25252VulnCheck
    · Fortinet FortiOS

    Fortinet FortiOS Insufficient Session Expiration

    VulnCheck recorded exploitation activity as of Sep 11, 2026

  • CVE-2023-34132VulnCheck
    · SonicWall Analytics

    SonicWall Analytics Use of Password Hash Instead of Password for Authentication

    VulnCheck recorded exploitation activity as of Aug 26, 2026

  • CVE-2026-63520VulnCheck
    · Microsoft SharePoint

    Microsoft SharePoint Improper Input Validation

    VulnCheck recorded exploitation activity as of Aug 25, 2026

  • CVE-2026-69836VulnCheck
    · Microsoft Entra Id

    Microsoft Entra Id Deserialization of Untrusted Data

    VulnCheck recorded exploitation activity as of Aug 20, 2026

  • CVE-2020-9771VulnCheck
    · Apple Mac OS X

    macOS APFS Snapshot Mount Authorization Bypass

    VulnCheck recorded exploitation activity as of Aug 13, 2026

  • CVE-2026-48294VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat and Reader Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Aug 10, 2026

  • CVE-2026-48313VulnCheck
    · Adobe ColdFusion

    Adobe ColdFusion Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    VulnCheck recorded exploitation activity as of Aug 1, 2026

  • CVE-2020-1013VulnCheck
    · Microsoft Windows

    Microsoft Windows Group Policy Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Jul 30, 2026

  • CVE-2025-62631VulnCheck
    · Fortinet FortiOS

    Fortinet FortiOS Insufficient Session Expiration

    VulnCheck recorded exploitation activity as of Jul 23, 2026

  • CVE-2026-45586VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Link Resolution Before File Access ('Link Following')

    VulnCheck recorded exploitation activity as of Jul 10, 2026

Show all 553 SMB-relevant (543 more)
  • CVE-2021-27076VulnCheck
    · Microsoft Business Productivity Servers

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Jun 24, 2026

  • CVE-2026-39813VulnCheck
    · Fortinet FortiSandbox

    Fortinet FortiSandbox Path Traversal: '../filedir'

    VulnCheck recorded exploitation activity as of Jun 15, 2026

  • CVE-2026-41089VulnCheck
    · Microsoft Windows

    Microsoft Windows Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of May 29, 2026

  • CVE-2024-12802VulnCheckKnown ransomware use
    · SonicWall SonicOS

    SonicWall SonicOS Authentication Bypass by Primary Weakness

    VulnCheck recorded exploitation activity as of May 19, 2026

  • CVE-2020-17103VulnCheck
    · Microsoft Windows

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of May 19, 2026

  • CVE-2025-40600VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS Use of Externally-Controlled Format String

    VulnCheck recorded exploitation activity as of May 10, 2026

  • CVE-2025-32818VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS NULL Pointer Dereference

    VulnCheck recorded exploitation activity as of May 10, 2026

  • CVE-2026-25187VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Link Resolution Before File Access ('Link Following')

    VulnCheck recorded exploitation activity as of Apr 13, 2026

  • CVE-2026-21262VulnCheck
    · Microsoft SQL Server 2016

    Microsoft SQL Server 2016 Improper Access Control

    VulnCheck recorded exploitation activity as of Apr 13, 2026

  • CVE-2026-26127VulnCheck
    · Microsoft .NET

    Microsoft .NET Out-of-bounds Read

    VulnCheck recorded exploitation activity as of Apr 13, 2026

  • CVE-2025-43532VulnCheck
    · Apple macOS

    Apple macOS Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

    VulnCheck recorded exploitation activity as of Apr 7, 2026

  • CVE-2025-43517VulnCheck
    · Apple macOS

    Apple macOS Sequoia/Sonoma/Tahoe Log Entry Data Redaction Vulnerability

    VulnCheck recorded exploitation activity as of Apr 7, 2026

  • CVE-2025-43542VulnCheck
    · Apple macOS

    Apple iOS/iPadOS/visionOS and macOS Sequoia/Tahoe FaceTime Password Disclosure

    VulnCheck recorded exploitation activity as of Apr 7, 2026

  • CVE-2025-46289VulnCheck
    · Apple macOS

    Apple macOS Improper Authorization

    VulnCheck recorded exploitation activity as of Apr 7, 2026

  • CVE-2025-24113VulnCheck
    · Apple Safari

    Apple Safari/iOS/iPadOS/visionOS/watchOS and macOS Sequoia Interface Spoofing Vulnerability

    VulnCheck recorded exploitation activity as of Apr 7, 2026

  • CVE-2025-43482VulnCheck
    · Apple macOS

    Apple macOS Improper Input Validation

    VulnCheck recorded exploitation activity as of Apr 7, 2026

  • CVE-2025-43512VulnCheck
    · Apple macOS

    Apple iOS/iPadOS and macOS Sequoia/Sonoma/Tahoe Privilege Escalation

    VulnCheck recorded exploitation activity as of Apr 7, 2026

  • CVE-2023-36899VulnCheck
    · Microsoft .NET Framework

    Microsoft .NET Framework Improper Input Validation

    VulnCheck recorded exploitation activity as of Mar 31, 2026

  • CVE-2014-6321VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Mar 23, 2026

  • CVE-2026-20931VulnCheck
    · Microsoft Windows

    Microsoft Windows External Control of File Name or Path

    VulnCheck recorded exploitation activity as of Feb 24, 2026

  • CVE-2026-20029VulnCheck
    · Cisco Identity Services Engine

    Cisco Identity Services Engine Improper Restriction of XML External Entity Reference

    VulnCheck recorded exploitation activity as of Feb 24, 2026

  • CVE-2023-39276VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Feb 5, 2026

  • CVE-2026-25815VulnCheck
    · Fortinet FortiOS

    Fortinet FortiOS LDAP Credentials Disclosure

    VulnCheck recorded exploitation activity as of Feb 5, 2026

  • CVE-2024-53705VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS Server-Side Request Forgery (SSRF)

    VulnCheck recorded exploitation activity as of Feb 5, 2026

  • CVE-2023-39280VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Feb 5, 2026

  • CVE-2023-39279VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Feb 5, 2026

  • CVE-2023-39278VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Feb 5, 2026

  • CVE-2025-40601VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Feb 5, 2026

  • CVE-2024-40762VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

    VulnCheck recorded exploitation activity as of Feb 5, 2026

  • CVE-2023-39277VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Feb 5, 2026

  • CVE-2024-20404VulnCheck
    · Cisco Finesse

    Cisco Finesse Server-Side Request Forgery (SSRF)

    VulnCheck recorded exploitation activity as of Feb 4, 2026

  • CVE-2020-16040VulnCheck
    · Google Chrome

    Google Chrome Improper Input Validation

    VulnCheck recorded exploitation activity as of Jan 26, 2026

  • CVE-2025-20282VulnCheck
    · Cisco Identity Services Engine

    Cisco Identity Services Engine Improper Privilege Management

    VulnCheck recorded exploitation activity as of Jan 20, 2026

  • CVE-2025-52665VulnCheck
    · Ubiquiti UniFi Access

    Ubiquiti UniFi Access Missing Authentication for Critical Function

    VulnCheck recorded exploitation activity as of Jan 16, 2026

  • CVE-2025-64155VulnCheck
    · Fortinet FortiSIEM

    Fortinet FortiSIEM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Jan 15, 2026

  • CVE-2023-44353VulnCheck
    · Adobe ColdFusion

    Adobe ColdFusion Deserialization of Untrusted Data

    VulnCheck recorded exploitation activity as of Dec 26, 2025

  • CVE-2023-44352VulnCheck
    · Adobe ColdFusion

    Adobe ColdFusion Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Dec 26, 2025

  • CVE-2025-59719VulnCheck
    · Fortinet FortiWeb

    Fortinet FortiWeb Improper Verification of Cryptographic Signature

    VulnCheck recorded exploitation activity as of Dec 15, 2025

  • CVE-2020-1066VulnCheckKnown ransomware use
    · Microsoft .NET Framework

    .NET Framework Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Dec 8, 2025

  • CVE-2025-9491VulnCheck
    · Microsoft Windows

    Microsoft Windows User Interface (UI) Misrepresentation of Critical Information

    VulnCheck recorded exploitation activity as of Oct 30, 2025

  • CVE-2025-54251VulnCheck
    · Adobe Experience Manager

    Adobe Experience Manager XML Injection (aka Blind XPath Injection)

    VulnCheck recorded exploitation activity as of Oct 28, 2025

  • CVE-2022-2915VulnCheck
    · SonicWall SMA 200 Firmware

    SonicWall SMA 200 Firmware Heap-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Oct 23, 2025

  • CVE-2023-5970VulnCheck
    · SonicWall SMA 200 Firmware

    SonicWall SMA 200 Firmware Improper Authentication

    VulnCheck recorded exploitation activity as of Oct 23, 2025

  • CVE-2025-24477VulnCheck
    · Fortinet FortiOS

    Fortinet FortiOS Heap-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Oct 23, 2025

  • CVE-2022-1703VulnCheck
    · SonicWall SMA 210 Firmware

    SonicWall SMA 210 Firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Oct 23, 2025

  • CVE-2024-20419VulnCheck
    · Cisco Smart Software Manager On-Prem

    Cisco Smart Software Manager On-Prem Unverified Password Change

    VulnCheck recorded exploitation activity as of Oct 17, 2025

  • CVE-2023-34124VulnCheck
    · SonicWall Analytics

    SonicWall Analytics Authentication Bypass by Primary Weakness

    VulnCheck recorded exploitation activity as of Oct 17, 2025

  • CVE-2025-54249VulnCheck
    · Adobe Experience Manager

    Adobe Experience Manager Server-Side Request Forgery (SSRF)

    VulnCheck recorded exploitation activity as of Oct 16, 2025

  • CVE-2025-53772VulnCheck
    · Microsoft Web Deploy 4.0

    Microsoft Web Deploy 4.0 Deserialization of Untrusted Data

    VulnCheck recorded exploitation activity as of Oct 7, 2025

  • CVE-2025-20363VulnCheck
    · Cisco IOS XR

    Cisco IOS XR Heap-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Oct 6, 2025

  • CVE-2025-52970VulnCheck
    · Fortinet FortiWeb

    Fortinet FortiWeb Improper Handling of Parameters

    VulnCheck recorded exploitation activity as of Sep 4, 2025

  • CVE-2022-20705VulnCheck
    · Cisco RV Series Routers

    Cisco RV Series Routers Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Sep 3, 2025

  • CVE-2025-47170VulnCheck
    · Microsoft Office

    Microsoft Office Use After Free

    VulnCheck recorded exploitation activity as of Sep 3, 2025

  • CVE-2025-47165VulnCheck
    · Microsoft Office

    Microsoft Office Use After Free

    VulnCheck recorded exploitation activity as of Sep 3, 2025

  • CVE-2022-35803VulnCheck
    · Microsoft Windows

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Aug 20, 2025

  • CVE-2022-24481VulnCheck
    · Microsoft Windows

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Aug 20, 2025

  • CVE-2020-1048VulnCheck
    · Microsoft Windows

    Microsoft Windows Incorrect Resource Transfer Between Spheres

    VulnCheck recorded exploitation activity as of Aug 20, 2025

  • CVE-2025-25256VulnCheck
    · Fortinet FortiSIEM

    Fortinet FortiSIEM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Aug 12, 2025

  • CVE-2025-54254VulnCheck
    · Adobe Experience Manager Forms

    Adobe Experience Manager Forms Improper Restriction of XML External Entity Reference

    VulnCheck recorded exploitation activity as of Aug 12, 2025

  • CVE-2024-38196VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Input Validation

    VulnCheck recorded exploitation activity as of Aug 4, 2025

  • CVE-2024-30090VulnCheckKnown ransomware use
    · Microsoft Windows

    Microsoft Windows Untrusted Pointer Dereference

    VulnCheck recorded exploitation activity as of Aug 1, 2025

  • CVE-2020-2034VulnCheck
    · Palo Alto Networks PAN-OS

    Palo Alto Networks PAN-OS Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Jul 31, 2025

  • CVE-2011-3315VulnCheck
    · Cisco Unified IP Interactive Voice Response

    Cisco Unified IP Interactive Voice Response Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    VulnCheck recorded exploitation activity as of Jul 31, 2025

  • CVE-2025-49533VulnCheck
    · Adobe Experience Manager

    Adobe Experience Manager Deserialization of Untrusted Data

    VulnCheck recorded exploitation activity as of Jul 30, 2025

  • CVE-2018-4237VulnCheck
    · Apple iPhone OS

    Apple iOS/macOS/tvOS/watchOS 'libxpc' Vulnerability

    VulnCheck recorded exploitation activity as of Jul 30, 2025

  • CVE-2025-53771VulnCheckKnown ransomware use
    · Microsoft SharePoint

    Microsoft SharePoint Improper Authentication

    VulnCheck recorded exploitation activity as of Jul 18, 2025

  • CVE-2023-20085VulnCheck
    · Cisco Identity Services Engine

    Cisco Identity Services Engine Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Jul 16, 2025

  • CVE-2022-41335VulnCheck
    · Fortinet FortiSwitchManager

    Fortinet FortiSwitchManager Relative Path Traversal

    VulnCheck recorded exploitation activity as of Jun 29, 2025

  • CVE-2025-0107VulnCheck
    · Palo Alto Networks Expedition

    Palo Alto Networks Expedition Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Jun 25, 2025

  • CVE-2009-1558VulnCheck
    · Cisco WVC54GCA

    Cisco WVC54GCA Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    VulnCheck recorded exploitation activity as of Jun 16, 2025

  • CVE-2025-47176VulnCheck
    · Microsoft Office

    Microsoft Office Path Traversal: '.../...//'

    VulnCheck recorded exploitation activity as of Jun 16, 2025

  • CVE-2024-21407VulnCheckKnown ransomware use
    · Microsoft Windows

    Microsoft Windows Use After Free

    VulnCheck recorded exploitation activity as of Jun 10, 2025

  • CVE-2025-20188VulnCheck
    · Cisco IOS XE

    Cisco IOS XE Use of Hard-coded Credentials

    VulnCheck recorded exploitation activity as of Jun 10, 2025

  • CVE-2020-16139VulnCheck
    · Cisco Unified IP Conference Station 7937G Firmware

    Cisco Unified IP Conference Station 7937G Crafted Packets Remote Denial of Service

    VulnCheck recorded exploitation activity as of Jun 8, 2025

  • CVE-2024-20440VulnCheck
    · Cisco Smart Licensing Utility

    Cisco Smart Licensing Utility Insertion of Sensitive Information into Log File

    VulnCheck recorded exploitation activity as of Jun 7, 2025

  • CVE-2020-3187VulnCheck
    · Cisco Secure Firewall Threat Defense

    Cisco Secure Firewall Threat Defense Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    VulnCheck recorded exploitation activity as of May 22, 2025

  • CVE-2000-0984VulnCheck
    · Cisco iOS

    Cisco iOS HTTP Server '?/' String Vulnerability

    VulnCheck recorded exploitation activity as of May 22, 2025

  • CVE-2018-0150VulnCheck
    · Cisco IOS XE

    Cisco IOS XE Use of Hard-coded Credentials

    VulnCheck recorded exploitation activity as of May 16, 2025

  • CVE-2018-0160VulnCheck
    · Cisco IOS XE

    Cisco IOS XE Double Free

    VulnCheck recorded exploitation activity as of May 16, 2025

  • CVE-2025-4664VulnCheck
    · Google Chrome

    Google Chrome Loader Policy Enforcement Vulnerability

    VulnCheck recorded exploitation activity as of May 14, 2025

  • CVE-2025-32819VulnCheck
    · SonicWall SMA 100 Appliances

    SonicWall SMA 100 Appliances Files or Directories Accessible to External Parties

    VulnCheck recorded exploitation activity as of May 7, 2025

  • CVE-2020-3529VulnCheck
    · Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

    Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Uncontrolled Resource Consumption

    VulnCheck recorded exploitation activity as of Apr 23, 2025

  • CVE-2024-38023VulnCheck
    · Microsoft SharePoint

    Microsoft SharePoint Deserialization of Untrusted Data

    VulnCheck recorded exploitation activity as of Apr 9, 2025

  • CVE-2024-38024VulnCheck
    · Microsoft SharePoint

    Microsoft SharePoint Deserialization of Untrusted Data

    VulnCheck recorded exploitation activity as of Apr 9, 2025

  • CVE-2024-20666VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Input Validation

    VulnCheck recorded exploitation activity as of Apr 3, 2025

  • CVE-2025-24061VulnCheck
    · Microsoft Windows

    Microsoft Windows Protection Mechanism Failure

    VulnCheck recorded exploitation activity as of Apr 3, 2025

  • CVE-2025-24071VulnCheck
    · Microsoft Windows

    Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor

    VulnCheck recorded exploitation activity as of Apr 3, 2025

  • CVE-2022-20933VulnCheck
    · Cisco Meraki MX64 Firmware

    Cisco Meraki MX64 Firmware Failure to Handle Missing Parameter

    VulnCheck recorded exploitation activity as of Mar 31, 2025

  • CVE-2017-0176VulnCheck
    · Microsoft Windows

    Microsoft Windows Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

    VulnCheck recorded exploitation activity as of Mar 12, 2025

  • CVE-2023-28218VulnCheck
    · Microsoft Windows

    Microsoft Windows Heap-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Mar 4, 2025

  • CVE-2024-28916VulnCheck
    · Microsoft Xbox Gaming Services

    Microsoft Xbox Gaming Services Improper Link Resolution Before File Access ('Link Following')

    VulnCheck recorded exploitation activity as of Feb 26, 2025

  • CVE-2024-21447VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Link Resolution Before File Access ('Link Following')

    VulnCheck recorded exploitation activity as of Feb 26, 2025

  • CVE-2024-38100VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Access Control

    VulnCheck recorded exploitation activity as of Feb 26, 2025

  • CVE-2024-23109VulnCheckKnown ransomware use
    · Fortinet FortiSIEM

    Fortinet FortiSIEM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Feb 25, 2025

  • CVE-2024-23108VulnCheckKnown ransomware use
    · Fortinet FortiSIEM

    Fortinet FortiSIEM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Feb 25, 2025

  • CVE-2025-0283VulnCheckKnown ransomware use
    · Ivanti Connect Secure, Policy Secure, and Neurons

    Ivanti Connect Secure, Policy Secure, and Neurons stack-based buffer overflow

    VulnCheck recorded exploitation activity as of Jan 8, 2025

  • CVE-2024-38653VulnCheck
    · Ivanti Avalanche

    Ivanti Avalanche Improper Restriction of XML External Entity Reference

    VulnCheck recorded exploitation activity as of Dec 12, 2024

  • CVE-2024-21390VulnCheck
    · Microsoft Authenticator

    Microsoft Authenticator Improper Authentication

    VulnCheck recorded exploitation activity as of Dec 5, 2024

  • CVE-2000-0325VulnCheck
    · Microsoft Jet

    Microsoft Jet Database Engine VBA Shell Vulnerability

    VulnCheck recorded exploitation activity as of Nov 20, 2024

  • CVE-2024-38021VulnCheck
    · Microsoft Office

    Microsoft Outlook Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Nov 20, 2024

  • CVE-2021-31969VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Privilege Management

    VulnCheck recorded exploitation activity as of Nov 19, 2024

  • CVE-2024-26229VulnCheck
    · Microsoft Windows CSC Service

    Windows CSC Service Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Nov 19, 2024

  • CVE-2024-50570VulnCheck
    · Fortinet FortiClient

    Fortinet FortiClient Cleartext Storage of Sensitive Information

    VulnCheck recorded exploitation activity as of Nov 15, 2024

  • CVE-2024-44258VulnCheck
    · Apple iPadOS

    Apple iPadOS Improper Link Resolution Before File Access ('Link Following')

    VulnCheck recorded exploitation activity as of Nov 2, 2024

  • CVE-2024-21894VulnCheck
    · Ivanti Connect Secure and Policy Secure

    Ivanti Connect Secure and Policy Secure Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Oct 30, 2024

  • CVE-2020-9910VulnCheck
    · Apple iCloud

    Apple iCloud Improper Authentication

    VulnCheck recorded exploitation activity as of Oct 29, 2024

  • CVE-2020-9870VulnCheck
    · Apple iPadOS

    Apple iPadOS Improper Input Validation

    VulnCheck recorded exploitation activity as of Oct 29, 2024

  • CVE-2023-20263VulnCheckKnown ransomware use
    · Cisco Hyperflex HX Data Platform

    Cisco Hyperflex HX Data Platform URL Redirection to Untrusted Site ('Open Redirect')

    VulnCheck recorded exploitation activity as of Oct 21, 2024

  • CVE-2024-9381VulnCheck
    · Ivanti CSA (Cloud Services Application)

    Ivanti CSA Path Traversal Security Bypass Vulnerability

    VulnCheck recorded exploitation activity as of Oct 8, 2024

  • CVE-2012-2626VulnCheck
    · SonicWall Scrutinizer

    SonicWall Scrutinizer Improper Authentication

    VulnCheck recorded exploitation activity as of Oct 1, 2024

  • CVE-2009-1872VulnCheck
    · Adobe ColdFusion

    Adobe ColdFusion Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Sep 19, 2024

  • CVE-2014-9792VulnCheck
    · Google Android

    Android Nexus 5 Qualcomm Components Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Sep 19, 2024

  • CVE-2020-3451VulnCheck
    · Cisco RV340W Firmware

    Cisco RV340W Firmware Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Sep 18, 2024

  • CVE-2022-20707VulnCheck
    · Cisco RV Series Routers

    Cisco RV Series Routers Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Sep 18, 2024

  • CVE-2023-0656VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Sep 12, 2024

  • CVE-2022-22274VulnCheck
    · SonicWall SonicOS

    SonicWall SonicOS Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Sep 12, 2024

  • CVE-2024-41869VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat and Reader Use After Free Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Sep 11, 2024

  • CVE-2024-43491VulnCheck
    · Microsoft Windows

    Microsoft Windows Update Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Sep 10, 2024

  • CVE-2008-3648VulnCheck
    · Microsoft Windows XP

    Microsoft Windows XP Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Aug 7, 2024

  • CVE-2021-28481VulnCheck
    · Microsoft Exchange Server

    Microsoft Exchange Server Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Jul 25, 2024

  • CVE-2022-22005VulnCheck
    · Microsoft SharePoint

    Microsoft SharePoint Deserialization of Untrusted Data

    VulnCheck recorded exploitation activity as of Jul 25, 2024

  • CVE-2024-21754VulnCheck
    · Fortinet FortiOS and FortiProxy

    Fortinet FortiOS and FortiProxy Backup File Weak Key Vulnerability

    VulnCheck recorded exploitation activity as of Jun 13, 2024

  • CVE-2018-4404VulnCheck
    · Apple iPhone OS

    Apple iPhone OS Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 29, 2024

  • CVE-2018-4233VulnCheck
    · Apple Safari

    Apple Safari Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 29, 2024

  • CVE-2023-36745VulnCheck
    · Microsoft Exchange Server

    Microsoft Exchange Server Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of May 24, 2024

  • CVE-2010-2506VulnCheck
    · Cisco Linksys Firmware

    Cisco Linksys Firmware Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of May 22, 2024

  • CVE-2023-41724VulnCheck
    · Ivanti Sentry

    Ivanti Sentry Improper Neutralization of Special Elements used in a Command ('Command Injection')

    VulnCheck recorded exploitation activity as of May 14, 2024

  • CVE-2023-46808VulnCheck
    · Ivanti Neurons For ITSM

    Ivanti Neurons For ITSM Unrestricted Upload of File with Dangerous Type

    VulnCheck recorded exploitation activity as of May 14, 2024

  • CVE-2024-20345VulnCheck
    · Cisco AppDynamics Controller

    Cisco AppDynamics Controller Directory Traversal Vulnerability

    VulnCheck recorded exploitation activity as of May 10, 2024

  • CVE-2020-1375VulnCheck
    · Microsoft Windows

    Windows COM Server Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of May 9, 2024

  • CVE-2021-26897VulnCheck
    · Microsoft Windows

    Windows DNS Server Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of May 7, 2024

  • CVE-2022-21907VulnCheck
    · Microsoft Windows

    HTTP Protocol Stack Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of May 7, 2024

  • CVE-2017-0068VulnCheck
    · Microsoft Edge

    Microsoft Edge Exposure of Sensitive Information to an Unauthorized Actor

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2021-30538VulnCheck
    · Google Chrome

    Google Chrome Incorrect Authorization

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2022-24463VulnCheck
    · Microsoft Exchange Server

    Microsoft Exchange Server Spoofing Vulnerability

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2013-2912VulnCheck
    · Google Chrome

    Google Chrome Pepper Plug-in API (PPAPI) PepperInProcessRouter::SendToHost Vulnerability

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2023-26397VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat and Reader Out-of-bounds Read

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2018-4312VulnCheck
    · Apple Safari

    Apple Safari Use After Free

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2018-4386VulnCheck
    · Apple Safari

    Apple Safari Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2017-13798VulnCheck
    · Apple Safari

    Apple Safari Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2017-16391VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat and Reader Improper Validation of Array Index

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2019-0537VulnCheck
    · Microsoft Visual Studio

    Microsoft Visual Studio Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2023-26347VulnCheck
    · Adobe ColdFusion

    Adobe ColdFusion Improper Access Control

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2018-5019VulnCheck
    · Adobe Acrobat DC

    Adobe Acrobat DC Out-of-bounds Read

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2018-4443VulnCheck
    · Apple Safari

    Apple Safari Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2016-3212VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2020-15994VulnCheck
    · Google Chrome

    Google Chrome Use After Free

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2017-16383VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat and Reader Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2019-0948VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Restriction of XML External Entity Reference

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2020-9802VulnCheck
    · Apple iCloud

    Apple iOS, iPadOS, tvOS, watchOS, Safari, iTunes for Windows, iCloud for Windows, iCloud for Windows Web Content Vulnerability

    VulnCheck recorded exploitation activity as of May 6, 2024

  • CVE-2023-34993VulnCheck
    · Fortinet FortiWLM

    Fortinet FortiWLM Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Apr 14, 2024

  • CVE-2024-26234VulnCheck
    · Microsoft Windows

    Proxy Driver Spoofing Vulnerability

    VulnCheck recorded exploitation activity as of Apr 9, 2024

  • CVE-2017-11884VulnCheck
    · Microsoft Excel

    Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Apr 4, 2024

  • CVE-2024-20720VulnCheck
    · Adobe Commerce

    Adobe Commerce Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Apr 4, 2024

  • CVE-2021-20039VulnCheck
    · SonicWall SMA 200 Firmware

    SonicWall SMA 200 Firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Mar 30, 2024

  • CVE-2023-21716VulnCheck
    · Microsoft Office

    Microsoft Word Remote Code Execution

    VulnCheck recorded exploitation activity as of Mar 21, 2024

  • CVE-2024-21888VulnCheck
    · Ivanti Connect Secure and Policy Secure

    Ivanti Connect Secure Privilege Escalation

    VulnCheck recorded exploitation activity as of Feb 29, 2024

  • CVE-2024-22024VulnCheck
    · Ivanti Connect Secure and Policy Secure

    Ivanti Connect Secure and Policy Secure Improper Restriction of XML External Entity Reference

    VulnCheck recorded exploitation activity as of Feb 6, 2024

  • CVE-2019-5782VulnCheck
    · Google Chrome

    Google Chrome Out-of-bounds Read

    VulnCheck recorded exploitation activity as of Feb 2, 2024

  • CVE-2021-30497VulnCheck
    · Ivanti Avalanche

    Ivanti Avalanche Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    VulnCheck recorded exploitation activity as of Jan 31, 2024

  • CVE-2023-29324VulnCheck
    · Microsoft Windows

    Windows MSHTML Platform Security Feature Bypass

    VulnCheck recorded exploitation activity as of Jan 30, 2024

  • CVE-2023-40088VulnCheck
    · Google Android

    Google Android Use After Free

    VulnCheck recorded exploitation activity as of Jan 30, 2024

  • CVE-2021-22122VulnCheck
    · Fortinet FortiWeb

    Fortinet FortiWeb Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Jan 22, 2024

  • CVE-2021-1733VulnCheck
    · Microsoft Psexec

    Microsoft Psexec Improper Privilege Management

    VulnCheck recorded exploitation activity as of Jan 16, 2024

  • CVE-2020-1206VulnCheck
    · Microsoft Windows

    Microsoft Windows Use of Uninitialized Resource

    VulnCheck recorded exploitation activity as of Dec 20, 2023

  • CVE-2023-21742VulnCheck
    · Microsoft SharePoint

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Dec 20, 2023

  • CVE-2010-1807VulnCheck
    · Apple Safari

    Apple Safari Improper Input Validation

    VulnCheck recorded exploitation activity as of Dec 7, 2023

  • CVE-2023-32563VulnCheck
    · Ivanti Avalanche

    Ivanti Avalanche Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    VulnCheck recorded exploitation activity as of Nov 16, 2023

  • CVE-2023-34133VulnCheck
    · SonicWall Analytics

    SonicWall Analytics Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    VulnCheck recorded exploitation activity as of Nov 16, 2023

  • CVE-2018-0127VulnCheck
    · Cisco RV Series Routers

    Cisco RV Series Routers Exposure of Sensitive Information to an Unauthorized Actor

    VulnCheck recorded exploitation activity as of Nov 15, 2023

  • CVE-2001-0537VulnCheck
    · Cisco iOS

    Cisco iOS Improper Authentication

    VulnCheck recorded exploitation activity as of Nov 15, 2023

  • CVE-2019-1821VulnCheck
    · Cisco Evolved Programmable Network Manager

    Cisco Evolved Programmable Network Manager Improper Input Validation

    VulnCheck recorded exploitation activity as of Nov 15, 2023

  • CVE-2023-20073VulnCheck
    · Cisco RV Series Routers

    Cisco RV Series Routers Unrestricted Upload of File with Dangerous Type

    VulnCheck recorded exploitation activity as of Nov 15, 2023

  • CVE-2021-21087VulnCheck
    · Adobe ColdFusion

    Adobe ColdFusion Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Nov 13, 2023

  • CVE-2021-1801VulnCheck
    · Apple iPadOS

    Apple macOS iframe Sandboxing Vulnerability

    VulnCheck recorded exploitation activity as of Sep 27, 2023

  • CVE-2019-5840VulnCheck
    · Google Chrome

    Google Chrome Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

    VulnCheck recorded exploitation activity as of Sep 27, 2023

  • CVE-2023-21746VulnCheck
    · Microsoft Windows

    Windows NTLM Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Sep 18, 2023

  • CVE-2022-2295VulnCheckKnown ransomware use
    · Google Chrome

    Google Chrome Access of Resource Using Incompatible Type ('Type Confusion')

    VulnCheck recorded exploitation activity as of Sep 5, 2023

  • CVE-2023-38204VulnCheck
    · Adobe ColdFusion

    Adobe ColdFusion Deserialization of Untrusted Data

    VulnCheck recorded exploitation activity as of Aug 30, 2023

  • CVE-2011-0105VulnCheck
    · Microsoft Excel

    Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Jul 19, 2023

  • CVE-2022-39952VulnCheck
    · Fortinet FortiNAC

    Fortinet FortiNAC External Control of File Name or Path

    VulnCheck recorded exploitation activity as of Jul 5, 2023

  • CVE-2022-46690VulnCheck
    · Apple iPadOS

    Apple iPadOS Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Jul 1, 2023

  • CVE-2019-0623VulnCheck
    · Microsoft Windows

    Win32k Elevation of Privilege

    VulnCheck recorded exploitation activity as of Jun 28, 2023

  • CVE-2023-32423VulnCheck
    · Apple Safari

    Apple Safari Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

    VulnCheck recorded exploitation activity as of May 18, 2023

  • CVE-2023-32402VulnCheck
    · Apple Safari

    Apple Safari Out-of-bounds Read

    VulnCheck recorded exploitation activity as of May 18, 2023

  • CVE-2022-22279VulnCheckKnown ransomware use
    · SonicWall SRA 1200 Firmware

    SonicWall SRA 1200 Firmware Relative Path Traversal

    VulnCheck recorded exploitation activity as of May 15, 2023

  • CVE-2023-24932VulnCheck
    · Microsoft Windows

    Secure Boot Security Feature Bypass Vulnerability

    VulnCheck recorded exploitation activity as of May 9, 2023

  • CVE-2022-30136VulnCheck
    · Microsoft Windows

    Windows Network File System Remote Code Execution

    VulnCheck recorded exploitation activity as of May 2, 2023

  • CVE-2023-21768VulnCheck
    · Microsoft Windows

    Windows Ancillary Function Driver for WinSock Privilege Escalation

    VulnCheck recorded exploitation activity as of Mar 14, 2023

  • CVE-2022-21894VulnCheck
    · Microsoft Windows

    Secure Boot Security Feature Bypass

    VulnCheck recorded exploitation activity as of Mar 1, 2023

  • CVE-2009-2521VulnCheckKnown ransomware use
    · Microsoft Internet Information Services (IIS)

    Microsoft Internet Information Services (IIS) Uncontrolled Resource Consumption

    VulnCheck recorded exploitation activity as of Feb 14, 2023

  • CVE-2020-1210VulnCheckKnown ransomware use
    · Microsoft SharePoint

    Microsoft SharePoint Download of Code Without Integrity Check

    VulnCheck recorded exploitation activity as of Feb 14, 2023

  • CVE-2023-23514VulnCheck
    · Apple iPadOS

    Apple iPadOS Use After Free

    VulnCheck recorded exploitation activity as of Feb 13, 2023

  • CVE-2023-23524VulnCheck
    · Apple iPadOS

    Apple iPadOS Uncontrolled Resource Consumption

    VulnCheck recorded exploitation activity as of Feb 13, 2023

  • CVE-2023-23522VulnCheck
    · Apple macOS

    macOS Ventura Temporary File Handling Vulnerability

    VulnCheck recorded exploitation activity as of Feb 13, 2023

  • CVE-2022-24500VulnCheckKnown ransomware use
    · Microsoft Windows

    Windows SMB Remote Code Execution

    VulnCheck recorded exploitation activity as of Jan 17, 2023

  • CVE-2022-0456VulnCheck
    · Google Chrome

    Google Chrome Use After Free

    VulnCheck recorded exploitation activity as of Jan 17, 2023

  • CVE-2022-46703VulnCheck
    · Apple iPadOS

    iPadOS, macOS Ventura, iOS and iPadOS Read Sensitive Location Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-42837VulnCheck
    · Apple iPadOS

    iOS and iPadOS, macOS Ventura, iOS and iPadOS, and watchOS 9.2 URL Parsing Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-46700VulnCheck
    · Apple Safari

    Apple Safari Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-46694VulnCheck
    · Apple iPadOS

    Apple iPadOS Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-46695VulnCheck
    · Apple iPadOS

    Apple iPadOS Improper Restriction of Rendered UI Layers or Frames

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-42840VulnCheck
    · Apple iPadOS

    macOS Monterey, macOS Ventura, macOS Big Sur, iOS and iPadOS Kernel Privilege App Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-46718VulnCheck
    · Apple iPadOS

    iOS and iPadOS, macOS Ventura, macOS Big Sur, and macOS Monterey App Sensitive Location Read Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-42855VulnCheck
    · Apple iPadOS

    tvOS, macOS Monterey, macOS Ventura, iOS and iPadOS App Arbitrary Entitlements Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-42846VulnCheck
    · Apple iPadOS

    iOS and iPadOS Malicious Video File System Termination Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-42861VulnCheck
    · Apple iPadOS

    iOS and iPadOS, macOS Monterey, and macOS Ventura App Sandbox Bypass Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-42848VulnCheck
    · Apple iPadOS

    iOS and iPadOS, and tvOS Kernel Privilege App Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-46692VulnCheck
    · Apple iCloud

    Safari, tvOS, iCloud for Windows, iOS, iPadOS, macOS Ventura, and watchOS Same Origin Policy Bypass Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2023-23496VulnCheck
    · Apple Safari

    macOS Ventura, watchOS, Safari, tvOS, iOS and iPadOS Maliciously Crafted Web Content Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-46689VulnCheck
    · Apple Safari

    Apple Safari Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-42864VulnCheck
    · Apple iPadOS

    Apple iPadOS Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-46705VulnCheck
    · Apple Safari

    iOS, iPadOS, macOS Ventura, and Safari URL Spoofing Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-42852VulnCheck
    · Apple Safari

    Safari, tvOS, macOS Ventura, watchOS 9.2, iOS and iPadOS Malicious Web Content Process Memory Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2022-46691VulnCheck
    · Apple Safari

    Apple Safari Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Dec 13, 2022

  • CVE-2021-34481VulnCheckKnown ransomware use
    · Microsoft Windows

    Microsoft Windows Improper Privilege Management

    VulnCheck recorded exploitation activity as of Nov 30, 2022

  • CVE-2021-42298VulnCheck
    · Microsoft Malware Protection Engine

    Microsoft Malware Protection Engine Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Nov 30, 2022

  • CVE-2022-34721VulnCheck
    · Microsoft Windows

    Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution

    VulnCheck recorded exploitation activity as of Nov 25, 2022

  • CVE-2020-1599VulnCheckKnown ransomware use
    · Microsoft Windows

    Windows Spoofing Vulnerability

    VulnCheck recorded exploitation activity as of Nov 14, 2022

  • CVE-2022-30170VulnCheck
    · Microsoft Windows

    Windows Credential Roaming Service Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Nov 8, 2022

  • CVE-2013-1300VulnCheck
    · Microsoft Windows

    Win32k Memory Allocation Vulnerability

    VulnCheck recorded exploitation activity as of Nov 3, 2022

  • CVE-2013-3881VulnCheck
    · Microsoft Windows

    Win32k NULL Page Vulnerability

    VulnCheck recorded exploitation activity as of Nov 3, 2022

  • CVE-2016-0095VulnCheck
    · Microsoft Windows

    Win32k Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Nov 3, 2022

  • CVE-2020-16875VulnCheckKnown ransomware use
    · Microsoft Exchange Server

    Microsoft Exchange Server Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

    VulnCheck recorded exploitation activity as of Oct 21, 2022

  • CVE-2021-33768VulnCheck
    · Microsoft Exchange Server

    Microsoft Exchange Server Privilege Escalation

    VulnCheck recorded exploitation activity as of Sep 14, 2022

  • CVE-2021-34470VulnCheck
    · Microsoft Exchange Server

    Microsoft Exchange Server Privilege Escalation

    VulnCheck recorded exploitation activity as of Sep 14, 2022

  • CVE-2018-6055VulnCheck
    · Google Chrome

    Google Chrome Improper Input Validation

    VulnCheck recorded exploitation activity as of Jul 20, 2022

  • CVE-2021-34730VulnCheckKnown ransomware use
    · Cisco Application Extension Platform

    Cisco Application Extension Platform Stack-based Buffer Overflow

    VulnCheck recorded exploitation activity as of Jun 22, 2022

  • CVE-2021-43207VulnCheckKnown ransomware use
    · Microsoft Windows

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Jun 13, 2022

  • CVE-2021-41349VulnCheck
    · Microsoft Exchange Server

    Microsoft Exchange Server Spoofing Vulnerability

    VulnCheck recorded exploitation activity as of May 31, 2022

  • CVE-2015-2551VulnCheckKnown ransomware use
    · Microsoft Windows

    VulnCheck recorded exploitation activity as of May 18, 2022

  • CVE-2019-8646VulnCheckKnown ransomware use
    · Apple iPhone OS

    Apple iPhone OS Out-of-bounds Read

    VulnCheck recorded exploitation activity as of May 18, 2022

  • CVE-2022-26809VulnCheckKnown ransomware use
    · Microsoft Windows

    Remote Procedure Call Runtime Remote Code Execution

    VulnCheck recorded exploitation activity as of Apr 14, 2022

  • CVE-2015-2370VulnCheck
    · Microsoft Windows

    Windows RPC Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Mar 16, 2022

  • CVE-2021-1636VulnCheck
    · Microsoft SQL Server

    Microsoft SQL Server Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    VulnCheck recorded exploitation activity as of Feb 24, 2022

  • CVE-2021-31206VulnCheckKnown ransomware use
    · Microsoft Exchange Server

    Microsoft Exchange Server Remote Code Execution

    VulnCheck recorded exploitation activity as of Jan 17, 2022

  • CVE-2015-0096VulnCheck
    · Microsoft Windows

    Microsoft Windows Untrusted Search Path

    VulnCheck recorded exploitation activity as of Dec 15, 2021

  • CVE-2010-2743VulnCheck
    · Microsoft Windows

    Microsoft Windows Win32k Keyboard Layout Privilege Escalation

    VulnCheck recorded exploitation activity as of Dec 15, 2021

  • CVE-2021-26885VulnCheck
    · Microsoft Windows

    Windows WalletService Privilege Escalation

    VulnCheck recorded exploitation activity as of Dec 15, 2021

  • CVE-2010-3338VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Input Validation

    VulnCheck recorded exploitation activity as of Dec 15, 2021

  • CVE-2021-30896VulnCheck
    · Apple iPadOS

    iOS and iPadOS, tvOS, watchOS, and macOS Monterey Gameplay Data Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Oct 11, 2021

  • CVE-2021-30895VulnCheck
    · Apple iPadOS

    iOS, iPadOS, tvOS, watchOS, and macOS Monterey App User Contact Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Oct 11, 2021

  • CVE-2021-1472VulnCheck
    · Cisco RV Series Routers

    Cisco RV Series Routers Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Oct 7, 2021

  • CVE-2021-1473VulnCheck
    · Cisco RV Series Routers

    Cisco RV Series Routers Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Oct 7, 2021

  • CVE-2019-1225VulnCheckKnown ransomware use
    · Microsoft Windows

    Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor

    VulnCheck recorded exploitation activity as of Aug 19, 2021

  • CVE-2019-1224VulnCheckKnown ransomware use
    · Microsoft Windows

    Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor

    VulnCheck recorded exploitation activity as of Aug 19, 2021

  • CVE-2019-1108VulnCheckKnown ransomware use
    · Microsoft Windows

    Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor

    VulnCheck recorded exploitation activity as of Aug 19, 2021

  • CVE-2020-16896VulnCheckKnown ransomware use
    · Microsoft Windows

    Windows Remote Desktop Protocol (RDP) Information Disclosure

    VulnCheck recorded exploitation activity as of Aug 19, 2021

  • CVE-2018-8114VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2021-28442VulnCheck
    · Microsoft Windows

    Windows TCP/IP Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2018-8275VulnCheck
    · Microsoft Edge

    Microsoft Edge Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-7242VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-3377VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2017-0067VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-3207VulnCheck
    · Microsoft Jscript

    Microsoft Jscript Improper Input Validation

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2017-0141VulnCheck
    · Microsoft Edge

    Microsoft Edge Scripting Engine Memory Corruption Vulnerability

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2011-0097VulnCheck
    · Microsoft Excel

    Microsoft Excel Integer Overrun Vulnerability

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2021-28324VulnCheck
    · Microsoft Windows

    Windows SMB Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2018-0955VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-3205VulnCheck
    · Microsoft Jscript

    Microsoft Jscript Improper Input Validation

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-7203VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-0191VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-3210VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2017-8598VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-5165VulnCheck
    · Google Chrome

    Google Chrome Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2010-3336VulnCheck
    · Microsoft Office

    Microsoft Office Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2018-8267VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2018-8122VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-3222VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2018-8133VulnCheck
    · Microsoft Edge

    Microsoft Edge Access of Resource Using Incompatible Type ('Type Confusion')

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-3206VulnCheck
    · Microsoft Jscript

    Microsoft Jscript Improper Input Validation

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2017-0015VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-0193VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2017-8605VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2017-8601VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2016-3199VulnCheck
    · Microsoft Edge

    Microsoft Edge Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2018-0953VulnCheck
    · Microsoft Edge

    Microsoft Edge Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2021-28482VulnCheckKnown ransomware use
    · Microsoft Exchange Server

    Microsoft Exchange Server Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Aug 17, 2021

  • CVE-2021-1765VulnCheck
    · Apple Mac OS X

    Apple macOS iframe Sandbox Enforcement Vulnerability

    VulnCheck recorded exploitation activity as of Aug 16, 2021

  • CVE-2021-30737VulnCheck
    · Apple iPadOS

    Apple iPadOS Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Jun 14, 2021

  • CVE-2019-0606VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Apr 12, 2021

  • CVE-2013-3128VulnCheck
    · Microsoft Windows

    Microsoft Windows OpenType Font Parsing Vulnerability

    VulnCheck recorded exploitation activity as of Feb 22, 2021

  • CVE-2016-4119VulnCheck
    · Apple Mac OS X

    Apple Mac OS X Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Jan 27, 2021

  • CVE-2018-8580VulnCheck
    · Microsoft SharePoint

    Microsoft SharePoint Exposure of Sensitive Information to an Unauthorized Actor

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2018-8622VulnCheck
    · Microsoft Windows

    Microsoft Windows Kernel Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2018-8627VulnCheck
    · Microsoft Excel

    Microsoft Excel Use of Uninitialized Resource

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2018-8477VulnCheck
    · Microsoft Windows

    Microsoft Windows Kernel Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2018-8595VulnCheck
    · Microsoft Windows

    Microsoft Windows GDI Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2018-8596VulnCheck
    · Microsoft Windows

    Windows GDI Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2018-8637VulnCheck
    · Microsoft Windows

    Microsoft Win32k Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2018-8621VulnCheck
    · Microsoft Windows

    Microsoft Windows Kernel Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2018-8638VulnCheck
    · Microsoft Windows

    Microsoft Windows DirectX Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2018-8598VulnCheck
    · Microsoft Excel

    Microsoft Excel Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2018-8514VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Initialization

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2018-8616VulnCheck
    · Microsoft Word

    Microsoft Word Information Disclosure Vulnerability

    VulnCheck recorded exploitation activity as of Jan 21, 2021

  • CVE-2001-0507VulnCheck
    · Microsoft Internet Information Server (IIS)

    Microsoft IIS 5.0 System file listing Privilege Escalation

    VulnCheck recorded exploitation activity as of Jan 5, 2021

  • CVE-2003-0050VulnCheck
    · Apple Darwin Streaming Server

    Apple Darwin Streaming Server Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Dec 1, 2020

  • CVE-2019-1040VulnCheck
    · Microsoft Windows

    Windows NTLM Tampering

    VulnCheck recorded exploitation activity as of Oct 20, 2020

  • CVE-2018-12808VulnCheckKnown ransomware use
    · Adobe Acrobat DC

    Adobe Acrobat DC Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Oct 15, 2020

  • CVE-2018-8389VulnCheckKnown ransomware use
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Oct 15, 2020

  • CVE-2018-8140VulnCheckKnown ransomware use
    · Microsoft Windows

    Cortana Elevation of Privilege

    VulnCheck recorded exploitation activity as of Oct 1, 2020

  • CVE-2018-0978VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Sep 15, 2020

  • CVE-2018-8641VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Resource Shutdown or Release

    VulnCheck recorded exploitation activity as of Jun 24, 2020

  • CVE-2019-11507VulnCheckKnown ransomware use
    · Ivanti Connect Secure and Policy Secure

    Ivanti Connect Secure and Policy Secure Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Jun 8, 2020

  • CVE-2018-4893VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat and Reader Out-of-bounds Read

    VulnCheck recorded exploitation activity as of Jun 3, 2020

  • CVE-2020-6453VulnCheck
    · Google Chrome

    Google Chrome Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Mar 26, 2020

  • CVE-2018-0986VulnCheckKnown ransomware use
    · Microsoft Exchange Server

    Microsoft Exchange Server Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Feb 25, 2020

  • CVE-2020-0651VulnCheckKnown ransomware use
    · Microsoft Excel

    Microsoft Excel Remote Code Execution

    VulnCheck recorded exploitation activity as of Jan 22, 2020

  • CVE-2020-0650VulnCheckKnown ransomware use
    · Microsoft Excel

    Microsoft Excel Remote Code Execution

    VulnCheck recorded exploitation activity as of Jan 22, 2020

  • CVE-2020-0640VulnCheckKnown ransomware use
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Jan 22, 2020

  • CVE-2020-0642VulnCheckKnown ransomware use
    · Microsoft Windows

    Microsoft Windows Use After Free

    VulnCheck recorded exploitation activity as of Jan 22, 2020

  • CVE-2020-0652VulnCheckKnown ransomware use
    · Microsoft Excel

    Microsoft Excel Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Jan 22, 2020

  • CVE-2020-0624VulnCheckKnown ransomware use
    · Microsoft Windows

    Win32k Elevation of Privilege

    VulnCheck recorded exploitation activity as of Jan 22, 2020

  • CVE-2020-0653VulnCheckKnown ransomware use
    · Microsoft Office

    Microsoft Excel Remote Code Execution

    VulnCheck recorded exploitation activity as of Jan 22, 2020

  • CVE-2020-0611VulnCheckKnown ransomware use
    · Microsoft Windows

    Remote Desktop Client Remote Code Execution

    VulnCheck recorded exploitation activity as of Jan 14, 2020

  • CVE-2020-0609VulnCheckKnown ransomware use
    · Microsoft Windows

    Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution

    VulnCheck recorded exploitation activity as of Jan 14, 2020

  • CVE-2020-0610VulnCheckKnown ransomware use
    · Microsoft Windows

    Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution

    VulnCheck recorded exploitation activity as of Jan 14, 2020

  • CVE-2013-3568VulnCheck
    · Cisco Linksys WRT110 Firmware

    Cisco Linksys WRT110 Firmware Cross-Site Request Forgery (CSRF)

    VulnCheck recorded exploitation activity as of Jan 8, 2020

  • CVE-2014-0498VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Dec 26, 2019

  • CVE-2019-8771VulnCheck
    · Apple Safari

    Apple Safari Improper Restriction of Rendered UI Layers or Frames

    VulnCheck recorded exploitation activity as of Sep 30, 2019

  • CVE-2017-13315VulnCheck
    · Google Android

    Google Android Incorrect Calculation of Buffer Size

    VulnCheck recorded exploitation activity as of Apr 12, 2019

  • CVE-2017-13156VulnCheck
    · Google Android

    Google Android Unrestricted Upload of File with Dangerous Type

    VulnCheck recorded exploitation activity as of Apr 12, 2019

  • CVE-2019-0667VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Apr 1, 2019

  • CVE-2019-0784VulnCheck
    · Microsoft Windows

    Microsoft Windows Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Apr 1, 2019

  • CVE-2019-0666VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Apr 1, 2019

  • CVE-2019-0633VulnCheck
    · Microsoft Windows

    Windows SMB Remote Code Execution

    VulnCheck recorded exploitation activity as of Apr 1, 2019

  • CVE-2019-0630VulnCheck
    · Microsoft Windows

    Windows SMB Remote Code Execution

    VulnCheck recorded exploitation activity as of Apr 1, 2019

  • CVE-2017-8750VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Mar 19, 2019

  • CVE-2016-0051VulnCheck
    · Microsoft Windows

    WebDAV Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Mar 6, 2019

  • CVE-2019-7816VulnCheck
    · Adobe ColdFusion

    Adobe ColdFusion Unrestricted Upload of File with Dangerous Type

    VulnCheck recorded exploitation activity as of Mar 1, 2019

  • CVE-2019-1663VulnCheck
    · Cisco RV110W Firmware

    Cisco RV110W Firmware Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Mar 1, 2019

  • CVE-2017-11869VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Nov 12, 2018

  • CVE-2018-15454VulnCheck
    · Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

    Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Improper Input Validation

    VulnCheck recorded exploitation activity as of Oct 31, 2018

  • CVE-2018-9866VulnCheck
    · SonicWall Global Management System

    SonicWall Global Management System Improper Neutralization of Special Elements used in a Command ('Command Injection')

    VulnCheck recorded exploitation activity as of Oct 27, 2018

  • CVE-2013-2678VulnCheck
    · Cisco Linksys E4200 Firmware

    Cisco Linksys E4200 Firmware Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

    VulnCheck recorded exploitation activity as of Jul 13, 2018

  • CVE-2014-6322VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Input Validation

    VulnCheck recorded exploitation activity as of Jun 20, 2018

  • CVE-2016-3225VulnCheck
    · Microsoft Windows

    Windows SMB Server Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Jun 1, 2018

  • CVE-2018-1038VulnCheck
    · Microsoft Windows

    Windows Kernel Elevation of Privilege

    VulnCheck recorded exploitation activity as of Jun 1, 2018

  • CVE-2007-5633VulnCheck
    · Microsoft Windows

    Alfredo Milani Comparetti SpeedFan 4.33 Speedfan.sys Privilege Escalation

    VulnCheck recorded exploitation activity as of Mar 6, 2018

  • CVE-2018-0101VulnCheck
    · Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

    Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Double Free

    VulnCheck recorded exploitation activity as of Jan 29, 2018

  • CVE-2005-2678VulnCheck
    · Microsoft Internet Information Services (IIS)

    Microsoft IIS SERVER_NAME Variable Bypass Vulnerability

    VulnCheck recorded exploitation activity as of Jan 15, 2018

  • CVE-2017-8487VulnCheck
    · Microsoft Windows

    Windows olecnv32.dll Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Nov 16, 2017

  • CVE-2003-0109VulnCheck
    · Microsoft Windows

    Microsoft Windows Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Jun 20, 2017

  • CVE-2009-2526VulnCheck
    · Microsoft Windows

    Microsoft Windows Mitigating Factors for SMBv2 Infinite Loop

    VulnCheck recorded exploitation activity as of Jun 20, 2017

  • CVE-2009-3103VulnCheckKnown ransomware use
    · Microsoft Windows

    Microsoft Windows SMBv2 srv2.sys Remote Code Execution

    VulnCheck recorded exploitation activity as of Jun 20, 2017

  • CVE-2004-0116VulnCheck
    · Microsoft Windows

    Microsoft Windows Uncontrolled Resource Consumption

    VulnCheck recorded exploitation activity as of Jun 20, 2017

  • CVE-2006-3439VulnCheck
    · Microsoft Windows

    Microsoft Windows Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Jun 20, 2017

  • CVE-2009-0099VulnCheck
    · Microsoft Exchange Server

    Microsoft Exchange Server Improper Input Validation

    VulnCheck recorded exploitation activity as of Jun 20, 2017

  • CVE-2009-2532VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Jun 20, 2017

  • CVE-2017-2404VulnCheck
    · Apple iPhone OS

    Apple iOS before 10.3 "Quick Look" Call Trigger

    VulnCheck recorded exploitation activity as of Apr 1, 2017

  • CVE-2014-0569VulnCheckKnown ransomware use
    · Adobe Flash Player

    Adobe Flash Player Integer Overflow or Wraparound

    VulnCheck recorded exploitation activity as of Dec 13, 2016

  • CVE-2011-0101VulnCheck
    · Microsoft Excel

    Microsoft Excel Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Sep 29, 2016

  • CVE-2014-0564VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Arbitrary Code Execution

    VulnCheck recorded exploitation activity as of Sep 29, 2016

  • CVE-2009-3674VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Uninitialized Memory Corruption

    VulnCheck recorded exploitation activity as of Sep 29, 2016

  • CVE-2013-5326VulnCheck
    · Adobe ColdFusion

    Adobe ColdFusion Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Sep 29, 2016

  • CVE-2006-3227VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer ASCII encoded Web filter bypass

    VulnCheck recorded exploitation activity as of Sep 29, 2016

  • CVE-2016-6909VulnCheck
    · Fortinet FortiOS

    Fortinet FortiOS Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Sep 28, 2016

  • CVE-2014-3393VulnCheck
    · Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)

    Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Improper Authentication

    VulnCheck recorded exploitation activity as of Sep 28, 2016

  • CVE-2014-4076VulnCheck
    · Microsoft Windows

    TCP/IP Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Aug 4, 2016

  • CVE-2016-0728VulnCheck
    · Google Android

    Google Android Integer Overflow or Wraparound

    VulnCheck recorded exploitation activity as of Aug 4, 2016

  • CVE-2016-0147VulnCheck
    · Microsoft XMP Core Services

    Microsoft XMP Core Services Improper Input Validation

    VulnCheck recorded exploitation activity as of Jun 14, 2016

  • CVE-2016-1409VulnCheck
    · Cisco iOS

    Cisco iOS Improper Input Validation

    VulnCheck recorded exploitation activity as of May 26, 2016

  • CVE-2010-1240VulnCheck
    · Adobe Acrobat and Reader

    Adobe Reader and Acrobat Launch File Warning Vulnerability

    VulnCheck recorded exploitation activity as of May 16, 2016

  • CVE-2015-1637VulnCheck
    · Microsoft Windows

    Schannel Security Feature Bypass Vulnerability

    VulnCheck recorded exploitation activity as of Apr 26, 2016

  • CVE-2001-0876VulnCheck
    · Microsoft Windows 98

    Microsoft Windows 98 Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Apr 26, 2016

  • CVE-2003-0818VulnCheck
    · Microsoft Windows

    Microsoft Windows Integer Overflow or Wraparound

    VulnCheck recorded exploitation activity as of Apr 26, 2016

  • CVE-2001-0877VulnCheck
    · Microsoft Windows 98

    Universal Plug and Play Unchecked Buffer Denial of Service

    VulnCheck recorded exploitation activity as of Apr 26, 2016

  • CVE-2015-1805VulnCheck
    · Google Android

    Linux kernel before 3.16 Pipe Read and Pipe Write I/O Vector Array Overrun

    VulnCheck recorded exploitation activity as of Mar 18, 2016

  • CVE-2016-0021VulnCheck
    · Microsoft Infopath

    Microsoft Infopath Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Mar 12, 2016

  • CVE-2011-1255VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Use of Uninitialized Resource

    VulnCheck recorded exploitation activity as of Feb 23, 2016

  • CVE-2015-8446VulnCheckKnown ransomware use
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Dec 22, 2015

  • CVE-2015-0359VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Double Free

    VulnCheck recorded exploitation activity as of Nov 9, 2015

  • CVE-2015-5560VulnCheck
    · Adobe Flash Player

    Adobe Flash Player, AIR, and AIR SDK Unspecified Arbitrary Code Execution

    VulnCheck recorded exploitation activity as of Nov 2, 2015

  • CVE-2015-0003VulnCheck
    · Microsoft Windows

    Microsoft Windows NULL Pointer Dereference

    VulnCheck recorded exploitation activity as of Nov 2, 2015

  • CVE-2015-3090VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Jul 30, 2015

  • CVE-2015-3104VulnCheck
    · Adobe Air

    Adobe Flash Player, AIR, and AIR SDK Unspecified Arbitrary Code Execution

    VulnCheck recorded exploitation activity as of Jul 30, 2015

  • CVE-2015-0349VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Use After Free

    VulnCheck recorded exploitation activity as of Jul 21, 2015

  • CVE-2015-3133VulnCheckKnown ransomware use
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Jun 29, 2015

  • CVE-2015-3105VulnCheckKnown ransomware use
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Jun 16, 2015

  • CVE-2015-0336VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Access of Resource Using Incompatible Type ('Type Confusion')

    VulnCheck recorded exploitation activity as of Jun 5, 2015

  • CVE-2015-0072VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Mar 10, 2015

  • CVE-2014-0311VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Feb 23, 2015

  • CVE-2013-3894VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Feb 1, 2015

  • CVE-2012-0159VulnCheck
    · Microsoft Office

    Microsoft Windows TrueType Font Parsing Vulnerability Remote Code Execution

    VulnCheck recorded exploitation activity as of Feb 1, 2015

  • CVE-2014-0556VulnCheckKnown ransomware use
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Oct 22, 2014

  • CVE-2014-0324VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Sep 18, 2014

  • CVE-2014-1809VulnCheck
    · Microsoft Office

    MSCOMCTL ASLR Vulnerability

    VulnCheck recorded exploitation activity as of May 14, 2014

  • CVE-2014-1815VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 13, 2014

  • CVE-2014-1807VulnCheck
    · Microsoft Windows

    Windows Shell File Association Vulnerability

    VulnCheck recorded exploitation activity as of May 13, 2014

  • CVE-2014-0515VulnCheckKnown ransomware use
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Apr 29, 2014

  • CVE-2014-0266VulnCheck
    · Microsoft Windows

    Microsoft Windows Exposure of Sensitive Information to an Unauthorized Actor

    VulnCheck recorded exploitation activity as of Feb 28, 2014

  • CVE-2014-0295VulnCheck
    · Microsoft .NET Framework

    VSAVB7RT ASLR Vulnerability

    VulnCheck recorded exploitation activity as of Feb 12, 2014

  • CVE-2014-0253VulnCheck
    · Microsoft .NET Framework

    Microsoft .NET Framework Improper Input Validation

    VulnCheck recorded exploitation activity as of Feb 11, 2014

  • CVE-2013-5330VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Feb 11, 2014

  • CVE-2012-0773VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Feb 1, 2014

  • CVE-2012-2520VulnCheck
    · Microsoft Groove Server

    Microsoft Groove Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Jan 15, 2014

  • CVE-2013-5331VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Dec 11, 2013

  • CVE-2013-5054VulnCheck
    · Microsoft Office

    Microsoft Office Exposure of Sensitive Information to an Unauthorized Actor

    VulnCheck recorded exploitation activity as of Dec 10, 2013

  • CVE-2013-5057VulnCheck
    · Microsoft Office

    Microsoft Office 2007 SP3 and 2010 SP1 and SP2 HXDS ASLR Vulnerability

    VulnCheck recorded exploitation activity as of Dec 10, 2013

  • CVE-2013-3336VulnCheck
    · Adobe ColdFusion

    Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 Remote File Read

    VulnCheck recorded exploitation activity as of May 14, 2013

  • CVE-2013-1389VulnCheck
    · Adobe ColdFusion

    Adobe ColdFusion Remote Code Execution

    VulnCheck recorded exploitation activity as of May 14, 2013

  • CVE-2013-1289VulnCheck
    · Microsoft Groove Server

    Microsoft Groove Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Apr 9, 2013

  • CVE-2009-3957VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat and Reader NULL Pointer Dereference

    VulnCheck recorded exploitation activity as of Mar 21, 2013

  • CVE-2012-4167VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Integer Overflow Remote Code Execution

    VulnCheck recorded exploitation activity as of Feb 12, 2013

  • CVE-2013-0633VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Feb 8, 2013

  • CVE-2013-0634VulnCheckKnown ransomware use
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Feb 8, 2013

  • CVE-2011-0559VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Nov 16, 2012

  • CVE-2010-1241VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat and Reader Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Oct 18, 2012

  • CVE-2009-0084VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Oct 18, 2012

  • CVE-2010-0480VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Oct 18, 2012

  • CVE-2009-3126VulnCheck
    · Microsoft Windows

    Microsoft GDI+ PNG Integer Overflow

    VulnCheck recorded exploitation activity as of Oct 18, 2012

  • CVE-2010-2862VulnCheck
    · Adobe Acrobat and Reader

    Adobe Reader CoolType.dll Remote Code Execution

    VulnCheck recorded exploitation activity as of Oct 18, 2012

  • CVE-2008-2249VulnCheck
    · Microsoft Windows

    Microsoft Windows Mitigating Factors for GDI Integer Overflow

    VulnCheck recorded exploitation activity as of Oct 18, 2012

  • CVE-2009-1134VulnCheck
    · Microsoft Office

    Microsoft Office Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Oct 18, 2012

  • CVE-2009-0561VulnCheck
    · Microsoft Office

    Microsoft Office Excel Record Integer Overflow

    VulnCheck recorded exploitation activity as of Oct 18, 2012

  • CVE-2011-0618VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Arbitrary Code Execution

    VulnCheck recorded exploitation activity as of Oct 18, 2012

  • CVE-2010-0028VulnCheck
    · Microsoft Windows

    MS Paint Integer Overflow Vulnerability

    VulnCheck recorded exploitation activity as of Oct 18, 2012

  • CVE-2009-2501VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Oct 18, 2012

  • CVE-2011-0227VulnCheck
    · Apple iPhone OS

    Apple iOS before 4.2.9 and 4.3.x before 4.3.4 IOMobileFrameBuffer Privilege Escalation

    VulnCheck recorded exploitation activity as of Oct 9, 2012

  • CVE-2012-1875VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Sep 1, 2012

  • CVE-2012-0779VulnCheck
    · Adobe Flash Player

    Adobe Flash Player object confusion Remote Code Execution

    VulnCheck recorded exploitation activity as of May 4, 2012

  • CVE-2012-0152VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Input Validation

    VulnCheck recorded exploitation activity as of Mar 13, 2012

  • CVE-2011-2140VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Feb 10, 2012

  • CVE-2012-0003VulnCheck
    · Microsoft Windows

    Windows Media Player (WMP) MIDI Remote Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of Jan 26, 2012

  • CVE-2011-3414VulnCheck
    · Microsoft Windows

    Microsoft .NET Framework CaseInsensitiveHashProvider.getHashCode Function Vulnerability

    VulnCheck recorded exploitation activity as of Jan 17, 2012

  • CVE-2011-1269VulnCheck
    · Microsoft Office

    Microsoft Office Improper Input Validation

    VulnCheck recorded exploitation activity as of Jan 1, 2012

  • CVE-2011-4369VulnCheck
    · Adobe Acrobat and Reader

    Adobe Reader and Acrobat PRC component Remote Code Execution

    VulnCheck recorded exploitation activity as of Dec 16, 2011

  • CVE-2010-3332VulnCheck
    · Microsoft .NET Framework

    Microsoft .NET Framework Generation of Error Message Containing Sensitive Information

    VulnCheck recorded exploitation activity as of Oct 26, 2011

  • CVE-2011-2444VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Sep 22, 2011

  • CVE-2011-1968VulnCheck
    · Microsoft Windows

    Remote Desktop Protocol Vulnerability

    VulnCheck recorded exploitation activity as of Aug 9, 2011

  • CVE-2010-1885VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    VulnCheck recorded exploitation activity as of Jul 26, 2011

  • CVE-2011-1249VulnCheck
    · Microsoft Windows

    Ancillary Function Driver Elevation of Privilege Vulnerability

    VulnCheck recorded exploitation activity as of Jun 30, 2011

  • CVE-2011-2110VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Jun 16, 2011

  • CVE-2011-2107VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Jun 6, 2011

  • CVE-2011-0094VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer 6 and 7 Layouts Handling Memory Corruption Vulnerability

    VulnCheck recorded exploitation activity as of May 16, 2011

  • CVE-2011-1345VulnCheck
    · Microsoft Internet Explorer

    Object Management Memory Corruption Vulnerability

    VulnCheck recorded exploitation activity as of May 16, 2011

  • CVE-2011-0627VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Input Validation

    VulnCheck recorded exploitation activity as of May 12, 2011

  • CVE-2008-1898VulnCheck
    · Microsoft Office

    Microsoft Office Improper Input Validation

    VulnCheck recorded exploitation activity as of Apr 21, 2011

  • CVE-2011-0096VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Apr 12, 2011

  • CVE-2010-3971VulnCheck
    · Microsoft Internet Explorer

    Microsoft CSS Memory Corruption Vulnerability

    VulnCheck recorded exploitation activity as of Mar 8, 2011

  • CVE-2010-3654VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Oct 29, 2010

  • CVE-2010-3653VulnCheck
    · Adobe Shockwave Player

    Adobe Shockwave Player Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Oct 21, 2010

  • CVE-2010-3889VulnCheck
    · Microsoft Windows

    Microsoft Windows 32-bit Platforms Unspecified Privilege Escalation

    VulnCheck recorded exploitation activity as of Oct 8, 2010

  • CVE-2010-3888VulnCheck
    · Microsoft Windows

    Microsoft Windows 32-bit Privilege Escalation

    VulnCheck recorded exploitation activity as of Oct 8, 2010

  • CVE-2010-2729VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Input Validation

    VulnCheck recorded exploitation activity as of Sep 15, 2010

  • CVE-2010-2884VulnCheck
    · Adobe Flash Player

    Adobe Flash Player Denial of Service

    VulnCheck recorded exploitation activity as of Sep 15, 2010

  • CVE-2010-1797VulnCheck
    · Apple iPhone OS

    Apple iPhone OS Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 5, 2010

  • CVE-2010-0817VulnCheck
    · Microsoft SharePoint

    Microsoft SharePoint Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of Jun 8, 2010

  • CVE-2004-0431VulnCheck
    · Apple QuickTime

    Apple QuickTime Integer Overflow or Wraparound

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2006-6027VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat Reader AcroPDF ActiveX Vulnerability

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2007-6166VulnCheck
    · Apple QuickTime

    Apple QuickTime Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2008-3008VulnCheck
    · Microsoft Windows Media Encoder

    Microsoft Windows Media Encoder Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2006-0005VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2006-5559VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Input Validation

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2009-1930VulnCheck
    · Microsoft Windows

    Microsoft Telnet Credential Reflection Vulnerability

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2006-0003VulnCheck
    · Microsoft Data Access Components

    Microsoft Data Access Components (MDAC) RDS.Dataspace ActiveX Control Vulnerability

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2004-1049VulnCheck
    · Microsoft Windows

    Microsoft Windows Integer Overflow or Wraparound

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2003-0111VulnCheck
    · Microsoft Virtual Machine

    Microsoft Virtual Machine ByteCode Verifier Component Code Execution Vulnerability

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2009-0075VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer 7 Uninitialized Memory Corruption Vulnerability

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2006-3643VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    VulnCheck recorded exploitation activity as of May 1, 2010

  • CVE-2009-1493VulnCheck
    · Adobe Acrobat and Reader

    Adobe Reader customDictionaryOpen Spell Method Vulnerability

    VulnCheck recorded exploitation activity as of Jan 20, 2010

  • CVE-2008-2042VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat and Reader Improper Input Validation

    VulnCheck recorded exploitation activity as of Jan 20, 2010

  • CVE-2009-1492VulnCheck
    · Adobe Acrobat and Reader

    Adobe Reader and Acrobat getAnnots Doc Method Vulnerability

    VulnCheck recorded exploitation activity as of Jan 20, 2010

  • CVE-2009-2990VulnCheck
    · Adobe Acrobat and Reader

    Adobe Reader and Acrobat Arbitrary Code Execution

    VulnCheck recorded exploitation activity as of Jan 20, 2010

  • CVE-2009-0555VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Nov 10, 2009

  • CVE-2009-2493VulnCheck
    · Microsoft Visual C\+\+

    Microsoft Active Template Library (ATL) COM Initialization Vulnerability

    VulnCheck recorded exploitation activity as of Nov 4, 2009

  • CVE-2009-3023VulnCheck
    · Microsoft Internet Information Services (IIS)

    Microsoft Internet Information Services (IIS) Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

    VulnCheck recorded exploitation activity as of Oct 19, 2009

  • CVE-2009-1923VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 18, 2009

  • CVE-2009-1536VulnCheck
    · Microsoft .NET Framework

    Microsoft .NET Framework Improper Input Validation

    VulnCheck recorded exploitation activity as of Aug 13, 2009

  • CVE-2009-1136VulnCheck
    · Microsoft Isa Server

    Microsoft Isa Server Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Jul 15, 2009

  • CVE-2009-0087VulnCheck
    · Microsoft Office

    WordPad and Office Text Converter Memory Corruption Vulnerability

    VulnCheck recorded exploitation activity as of Jun 17, 2009

  • CVE-2008-1436VulnCheck
    · Microsoft Windows

    Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 Privilege Escalation

    VulnCheck recorded exploitation activity as of Apr 14, 2009

  • CVE-2009-0080VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Privilege Management

    VulnCheck recorded exploitation activity as of Apr 14, 2009

  • CVE-2009-0078VulnCheck
    · Microsoft Windows

    Windows WMI Service Isolation Vulnerability

    VulnCheck recorded exploitation activity as of Apr 14, 2009

  • CVE-2009-0079VulnCheck
    · Microsoft Windows

    Windows RPCSS Service Isolation Vulnerability

    VulnCheck recorded exploitation activity as of Apr 14, 2009

  • CVE-2007-0015VulnCheck
    · Apple QuickTime

    Apple QuickTime Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Mar 20, 2009

  • CVE-2009-0658VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat and Reader Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Feb 20, 2009

  • CVE-2008-4844VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer CRecordInstance::TransferToDestination Remote Code Execution

    VulnCheck recorded exploitation activity as of Dec 11, 2008

  • CVE-2008-4841VulnCheck
    · Microsoft WordPad

    WordPad Word 97 Text Converter Stack Overflow Vulnerability

    VulnCheck recorded exploitation activity as of Dec 10, 2008

  • CVE-2008-1446VulnCheck
    · Microsoft Internet Information Services (IIS)

    Microsoft Internet Information Services (IIS) Integer Overflow or Wraparound

    VulnCheck recorded exploitation activity as of Oct 29, 2008

  • CVE-2008-2463VulnCheck
    · Microsoft Office

    Microsoft Office Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Oct 15, 2008

  • CVE-2008-0081VulnCheck
    · Microsoft Excel

    Microsoft Excel Use of Uninitialized Resource

    VulnCheck recorded exploitation activity as of Oct 1, 2008

  • CVE-2006-5758VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Sep 26, 2008

  • CVE-2008-3873VulnCheck
    · Adobe Flash Player

    Adobe Flash Player 9.0.124.0 and earlier System.setClipboard method in ActionScript Vulnerability

    VulnCheck recorded exploitation activity as of Aug 29, 2008

  • CVE-2008-3704VulnCheck
    · Microsoft Visual Basic

    Microsoft Visual Basic Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 18, 2008

  • CVE-2008-2244VulnCheck
    · Microsoft Office

    Microsoft Office Word 2002 SP3 Malformed Data Remote Code Execution

    VulnCheck recorded exploitation activity as of Jul 9, 2008

  • CVE-2008-2641VulnCheck
    · Adobe Acrobat 3D

    Adobe Reader and Acrobat 7.0.9 and earlier, and 8.0 through 8.1.2 Input Validation in a JavaScript Method Vulnerability

    VulnCheck recorded exploitation activity as of Jun 25, 2008

  • CVE-2007-0071VulnCheck
    · Adobe Flash Player

    Adobe Flash Player SWF Negative Scene Count Vulnerability

    VulnCheck recorded exploitation activity as of May 28, 2008

  • CVE-2007-6026VulnCheck
    · Microsoft Jet

    Microsoft Jet Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 13, 2008

  • CVE-2008-1092VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Mar 25, 2008

  • CVE-2007-5347VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer 5.01 through 7 DHTML Object Memory Corruption Vulnerability

    VulnCheck recorded exploitation activity as of Dec 20, 2007

  • CVE-2007-5587VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Dec 11, 2007

  • CVE-2007-3896VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Input Validation

    VulnCheck recorded exploitation activity as of Nov 13, 2007

  • CVE-2007-5020VulnCheck
    · Adobe Acrobat and Reader

    Adobe Acrobat and Reader Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Oct 26, 2007

  • CVE-2007-3899VulnCheck
    · Microsoft Office

    Microsoft Office Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Oct 9, 2007

  • CVE-2003-0352VulnCheck
    · Microsoft Windows

    Microsoft Windows Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Sep 7, 2007

  • CVE-2007-1070VulnCheck
    · Microsoft Windows

    Microsoft Windows Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Aug 25, 2007

  • CVE-2007-1748VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of May 8, 2007

  • CVE-2007-0870VulnCheck
    · Microsoft Word

    Word Document Stream Vulnerability

    VulnCheck recorded exploitation activity as of May 8, 2007

  • CVE-2007-0038VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Apr 3, 2007

  • CVE-2007-1765VulnCheck
    · Microsoft Windows

    Microsoft Windows Cursor, Animated Cursor, and Icon Processing Vulnerability

    VulnCheck recorded exploitation activity as of Mar 30, 2007

  • CVE-2007-0515VulnCheck
    · Microsoft Office

    Word Malformed Function Vulnerability

    VulnCheck recorded exploitation activity as of Feb 13, 2007

  • CVE-2006-6456VulnCheck
    · Microsoft Office

    Word Malformed Data Structures Vulnerability

    VulnCheck recorded exploitation activity as of Feb 13, 2007

  • CVE-2006-6561VulnCheck
    · Microsoft Office

    Microsoft Word Count Vulnerability

    VulnCheck recorded exploitation activity as of Feb 13, 2007

  • CVE-2006-5994VulnCheck
    · Microsoft Office

    Word Malformed String Vulnerability

    VulnCheck recorded exploitation activity as of Feb 13, 2007

  • CVE-2007-0024VulnCheck
    · Microsoft Windows

    Microsoft Windows Integer Overflow or Wraparound

    VulnCheck recorded exploitation activity as of Jan 9, 2007

  • CVE-2006-4704VulnCheck
    · Microsoft Visual Studio

    Microsoft Visual Studio 2005 WMI Object Broker Vulnerability

    VulnCheck recorded exploitation activity as of Jan 9, 2007

  • CVE-2006-4446VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Nov 14, 2006

  • CVE-2006-4777VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Nov 14, 2006

  • CVE-2006-5745VulnCheck
    · Microsoft XMP Core Services

    Microsoft XML Core Services Vulnerability

    VulnCheck recorded exploitation activity as of Nov 14, 2006

  • CVE-2006-4534VulnCheck
    · Microsoft Office

    Microsoft Word Malformed Stack Vulnerability

    VulnCheck recorded exploitation activity as of Oct 10, 2006

  • CVE-2006-4694VulnCheck
    · Microsoft Office

    Microsoft Office Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Oct 10, 2006

  • CVE-2006-3730VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Oct 10, 2006

  • CVE-2006-4868VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Sep 26, 2006

  • CVE-2006-3649VulnCheck
    · Microsoft Visual Basic

    Microsoft Visual Basic Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Aug 8, 2006

  • CVE-2006-3590VulnCheck
    · Microsoft PowerPoint

    Microsoft PowerPoint Mso.dll Vulnerability

    VulnCheck recorded exploitation activity as of Aug 8, 2006

  • CVE-2006-1301VulnCheck
    · Microsoft Excel

    Microsoft Excel Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Jul 11, 2006

  • CVE-2006-1540VulnCheck
    · Microsoft Office

    Microsoft Office Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Jul 11, 2006

  • CVE-2006-3059VulnCheck
    · Microsoft Excel

    Microsoft Excel Malformed file Vulnerability

    VulnCheck recorded exploitation activity as of Jul 11, 2006

  • CVE-2006-1359VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Control of Generation of Code ('Code Injection')

    VulnCheck recorded exploitation activity as of Apr 11, 2006

  • CVE-2006-0009VulnCheck
    · Microsoft Office

    Microsoft Office Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Mar 14, 2006

  • CVE-2005-4560VulnCheck
    · Microsoft Windows

    Microsoft Windows Improper Input Validation

    VulnCheck recorded exploitation activity as of Dec 28, 2005

  • CVE-2005-1790VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Javascript BODY onload Vulnerability

    VulnCheck recorded exploitation activity as of Dec 13, 2005

  • CVE-2000-0884VulnCheck
    · Microsoft Internet Information Services (IIS)

    Microsoft IIS 4.0 and 5.0 Folder Traversal Vulnerability

    VulnCheck recorded exploitation activity as of Aug 25, 2005

  • CVE-2001-0154VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer HTML E-mail Feature Vulnerability

    VulnCheck recorded exploitation activity as of Aug 25, 2005

  • CVE-2005-1983VulnCheck
    · Microsoft Windows

    Microsoft Windows Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Aug 9, 2005

  • CVE-2005-1219VulnCheck
    · Microsoft Image Color Management

    Microsoft Image Color Management Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Jul 12, 2005

  • CVE-2005-2087VulnCheck
    · Microsoft Internet Explorer

    Microsoft IE 5.01 SP4 up to 6 javaprxy.dll COM Instantiation Heap Corruption Vulnerability

    VulnCheck recorded exploitation activity as of Jul 12, 2005

  • CVE-2004-0847VulnCheck
    · Microsoft Asp.net

    Microsoft Asp.net Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    VulnCheck recorded exploitation activity as of Feb 8, 2005

  • CVE-2005-0053VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Drag-and-Drop Vulnerability

    VulnCheck recorded exploitation activity as of Feb 8, 2005

  • CVE-2004-1043VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer HTML Help ActiveX control Cross Domain Vulnerability

    VulnCheck recorded exploitation activity as of Jan 11, 2005

  • CVE-2004-0727VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Similar Method Name Redirection Cross Domain Vulnerability

    VulnCheck recorded exploitation activity as of Nov 9, 2004

  • CVE-2004-0566VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Integer Overflow or Wraparound

    VulnCheck recorded exploitation activity as of Jul 30, 2004

  • CVE-2004-0549VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer showModalDialog Method Vulnerability

    VulnCheck recorded exploitation activity as of Jul 30, 2004

  • CVE-2003-1041VulnCheck
    · Microsoft Internet Explorer

    Microsoft Internet Explorer Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    VulnCheck recorded exploitation activity as of Jul 13, 2004

  • CVE-2003-0533VulnCheck
    · Microsoft Netmeeting

    Microsoft Netmeeting Out-of-bounds Write

    VulnCheck recorded exploitation activity as of May 13, 2004

  • CVE-2004-0380VulnCheck
    · Microsoft Outlook Express

    Microsoft Outlook Express MHTML URL Processing Vulnerability

    VulnCheck recorded exploitation activity as of Feb 13, 2004

  • CVE-2002-0649VulnCheck
    · Microsoft Data Engine

    Microsoft Data Engine Improper Restriction of Operations within the Bounds of a Memory Buffer

    VulnCheck recorded exploitation activity as of Aug 1, 2003

  • CVE-2003-0605VulnCheck
    · Microsoft Windows

    Windows 2000 SP3 and SP4 PerformScmStage function Vulnerability

    VulnCheck recorded exploitation activity as of Aug 1, 2003

  • CVE-2002-1717VulnCheck
    · Microsoft Internet Information Services (IIS)

    Microsoft Internet Information Services (IIS) Exposure of Sensitive Information to an Unauthorized Actor

    VulnCheck recorded exploitation activity as of Dec 31, 2002

  • CVE-2001-0500VulnCheck
    · Microsoft Index Server

    Microsoft Index Server Out-of-bounds Write

    VulnCheck recorded exploitation activity as of Jul 19, 2001

  • CVE-2001-0333VulnCheck
    · Microsoft Internet Information Services (IIS)

    Microsoft Internet Information Services (IIS) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    VulnCheck recorded exploitation activity as of Mar 18, 2001

  • CVE-2000-0071VulnCheck
    · Microsoft Internet Information Services (IIS)

    Microsoft Internet Information Services (IIS) Exposure of Sensitive Information to an Unauthorized Actor

    VulnCheck recorded exploitation activity as of Jan 11, 2000

VulnCheck also tracks 3,136 exploited CVEs outside the SMB-relevant vendor allowlist — gear we don't typically see in dental, law, or accounting shops. Full exploited-not-on-CISA breadth: 3,689.

Breadth data via VulnCheck KEV.

Last 90 days

Added recently.

New SMB-relevant additions to KEV in the last 90 days — the urgent items most likely to need action this quarter.

  • CVE-2026-104286 · Fortinet FortiMailPath Traversal VulnerabilityPatch secondAdded to KEV Oct 1, 2026

    Fortinet FortiMail Path Traversal Vulnerability

    Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.

    Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

  • CVE-2026-76504 · Cisco Catalyst SD-WAN ManagerHex Encoding VulnerabilityPatch secondAdded to KEV Sep 30, 2026

    Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

    Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.

    Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

  • CVE-2026-86950 · Apple Multiple ProductsOut-of-Bounds Write VulnerabilityPatch thirdAdded to KEV Sep 29, 2026

    Apple Multiple Products Out-of-Bounds Write Vulnerability

    Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.

    Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

  • CVE-2026-65660 · Microsoft SharePointCode Injection VulnerabilityPatch thirdAdded to KEV Sep 25, 2026

    Microsoft SharePoint Code Injection Vulnerability

    Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.

    Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

  • CVE-2026-71362 · Adobe Commerce and MagentoIncorrect Authorization VulnerabilityPatch secondAdded to KEV Sep 24, 2026

    Adobe Commerce and Magento Incorrect Authorization Vulnerability

    Affects anyone running Adobe Commerce and Magento. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.

    Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

  • CVE-2026-76460 · Cisco Identity Services EngineIncorrect Use of Privileged APIs VulnerabilityPatch secondAdded to KEV Sep 16, 2026

    Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

    Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.

    Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

  • CVE-2026-58704 · Google PixelImproper Authorization VulnerabilityPatch thirdAdded to KEV Sep 16, 2026

    Google Pixel Improper Authorization Vulnerability

    Affects anyone running Google Pixel. Google products typically sit at the identity or browsing layer — exploitation usually affects access to cloud services and stored sessions.

    Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.

  • CVE-2026-76461 · Cisco Secure Email GatewaySQL Injection VulnerabilityPatch secondAdded to KEV Sep 14, 2026

    Cisco Secure Email Gateway SQL Injection Vulnerability

    Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.

    Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

  • CVE-2025-25249 · Fortinet Multiple ProductsHeap-based Buffer Overflow VulnerabilityPatch secondAdded to KEV Sep 9, 2026

    Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

    Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.

    Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

  • CVE-2026-20079 · Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementFirewall Management Center Authentication Bypass Using an Alternate Path or Channel VulnerabilityPatch secondAdded to KEV Sep 9, 2026

    Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.

    Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

  • CVE-2026-87491 · Google Chromium V8Out of Bounds Write VulnerabilityPatch thirdAdded to KEV Sep 9, 2026

    Google Chromium V8 Out of Bounds Write Vulnerability

    Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.

    Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • CVE-2026-75650 · Adobe Commerce and MagentoImproper Neutralization of Special Elements Used in a Template Engine VulnerabilityPatch secondAdded to KEV Sep 8, 2026

    Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Affects anyone running Adobe Commerce and Magento. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.

    Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

  • Microsoft Windows: 2 CVEsPatch thirdadded Sep 8, 2026
    • Microsoft Windows Heap-Based Buffer Overflow Vulnerability

      Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.

      Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

      • KB5122876
      • KB5122882
      • KB5122878
      • KB5123099
      • +2 more
    • Microsoft Windows Link Following Vulnerability

      Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.

      Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

      • KB5122871
      • KB5124008
      • KB5122880
      • KB5124012
  • CVE-2026-85046 · Google Chromium V8Type Confusion VulnerabilityPatch thirdAdded to KEV Sep 4, 2026

    Google Chromium V8 Type Confusion Vulnerability

    Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.

    Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • SonicWall SMA1000 Appliances: 2 CVEsPatch secondadded Sep 2, 2026
    • SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

      Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.

      SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

    • SonicWall SMA1000 Appliances OS Command Injection Vulnerability

      Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.

      SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

  • CVE-2019-1068 · Microsoft SQL ServerRemote Code Execution VulnerabilityPatch thirdAdded to KEV Aug 26, 2026

    Microsoft SQL Server Remote Code Execution Vulnerability

    Affects anyone running Microsoft SQL Server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.

    Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

  • CVE-2026-33824 · Microsoft Internet Key Exchange (IKE) Service ExtensionsDouble Free VulnerabilityPatch secondAdded to KEV Aug 18, 2026

    Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

    Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.

    Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

  • CVE-2026-55040 · Microsoft SharePointWeak Authentication VulnerabilityPatch secondAdded to KEV Aug 18, 2026

    Microsoft SharePoint Weak Authentication Vulnerability

    Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.

    Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-65400 · Apple macOSImproper Authentication VulnerabilityPatch secondAdded to KEV Aug 18, 2026

    Apple macOS Improper Authentication Vulnerability

    Affects anyone running Macs, iPhones, or iPads in the office. For a small practice, Apple endpoints are typically how staff handle email, browse client portals, and store local case files — exploitation gives an attacker access to that data on the device.

    Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

  • CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)Heap Inspection VulnerabilityPatch secondAdded to KEV Aug 11, 2026

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

    Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

  • CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSockUse-After-Free VulnerabilityPatch thirdAdded to KEV Aug 11, 2026

    Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

    Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.

    Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

    • KB5120238
    • KB5120242
    • KB5120229
    • KB5120249
    • +9 more
  • CVE-2026-20316 · Cisco Secure Firewall Management Center (FMC)Secure Firewall Management Center Use of Hard-coded Password VulnerabilityKnown ransomware usePatch firstAdded to KEV Jul 29, 2026

    Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

    Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.

    Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

  • CVE-2025-68686 · Fortinet FortiOSExposure of Sensitive Information to an Unauthorized Actor VulnerabilityPatch thirdAdded to KEV Jul 27, 2026

    Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

    Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.

    Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

  • CVE-2026-50522 · Microsoft SharePointDeserialization of Untrusted Data VulnerabilityPatch secondAdded to KEV Jul 22, 2026

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.

    Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

  • CVE-2026-58644 · Microsoft SharePointDeserialization of Untrusted Data VulnerabilityPatch secondAdded to KEV Jul 16, 2026

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.

    Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

  • Fortinet FortiSandbox: 2 CVEsPatch secondadded Jul 16, 2026
    • Fortinet FortiSandbox OS Command Injection Vulnerability

      Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.

      Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

    • Fortinet FortiSandbox OS Command Injection Vulnerability

      Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.

      Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

  • SonicWall SMA1000 Appliances: 2 CVEsPatch firstadded Jul 14, 2026
    • CVE-2026-15409Known ransomware use

      SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

      Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.

      SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

    • CVE-2026-15410Known ransomware use

      SonicWall SMA1000 Appliances Code Injection Vulnerability

      Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.

      SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

  • CVE-2026-56155 · Microsoft Active Directory Federation ServicesInsufficient Granularity of Access Control VulnerabilityPatch thirdAdded to KEV Jul 14, 2026

    Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

    Affects anyone running Microsoft Active Directory Federation Services. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.

    Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

    • KB5099538
    • KB5099540
    • KB5099536
    • KB5099535
    • +2 more
  • CVE-2026-56164 · Microsoft SharePoint ServerMissing Authentication for Critical Function VulnerabilityPatch fourthAdded to KEV Jul 14, 2026

    Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

    Affects anyone running Microsoft SharePoint Server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.

    Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2008-4128 · Cisco iOSCross-Site Request Forgery VulnerabilityPatch secondAdded to KEV Jul 13, 2026

    Cisco iOS Cross-Site Request Forgery Vulnerability

    Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.

    Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.

Earlier

Older entries still worth a check.

The most recent SMB-relevant entries that predate the 90-day window above. Use the search bar to reach anything older.

  • CVE-2026-48282 · Adobe ColdFusionPath Traversal VulnerabilityPatch secondAdded to KEV Jul 7, 2026

    Adobe ColdFusion Path Traversal Vulnerability

    Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.

    Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

  • CVE-2026-45659 · Microsoft SharePoint ServerDeserialization of Untrusted Data VulnerabilityKnown ransomware usePatch firstAdded to KEV Jul 1, 2026

    Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

    Affects anyone running Microsoft SharePoint Server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.

    Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

  • CVE-2026-20230 · Cisco Unified Communications ManagerServer-Side Request Forgery (SSRF) VulnerabilityPatch secondAdded to KEV Jun 25, 2026

    Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

    Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.

    Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

  • Ubiquiti UniFi OS: 3 CVEsPatch secondadded Jun 23, 2026
    • Ubiquiti UniFi OS Improper Input Validation Vulnerability

      Affects anyone running Ubiquiti UniFi networking gear (access points, switches, security gateways, NVRs). The gear carries internal network traffic and often hosts video surveillance — exploitation can expose network traffic or grant management access to the network itself.

      Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.

    • Ubiquiti UniFi OS Path Traversal Vulnerability

      Affects anyone running Ubiquiti UniFi networking gear (access points, switches, security gateways, NVRs). The gear carries internal network traffic and often hosts video surveillance — exploitation can expose network traffic or grant management access to the network itself.

      Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

    • Ubiquiti UniFi OS Improper Access Control Vulnerability

      Affects anyone running Ubiquiti UniFi networking gear (access points, switches, security gateways, NVRs). The gear carries internal network traffic and often hosts video surveillance — exploitation can expose network traffic or grant management access to the network itself.

      Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.

  • CVE-2026-20262 · Cisco Catalyst SD-WAN ManagerDirectory or Path Traversal VulnerabilityPatch thirdAdded to KEV Jun 15, 2026

    Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

    Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.

    Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.

  • CVE-2026-10520 · Ivanti SentryOS Command Injection VulnerabilityPatch secondAdded to KEV Jun 11, 2026

    Ivanti Sentry OS Command Injection Vulnerability

    Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.

    Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

  • CVE-2026-11645 · Google Chromium V8Out-of-Bounds Read and Write VulnerabilityPatch thirdAdded to KEV Jun 9, 2026

    Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

    Affects anyone using Chrome or Chromium as their browser. The browser is where staff log into cloud apps, banking, and client portals — exploitation can mean session theft or credential exposure for every site you're signed into.

    Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • CVE-2026-20245 · Cisco Catalyst SD-WAN ManagerImproper Encoding or Escaping of Output VulnerabilityPatch secondAdded to KEV Jun 9, 2026

    Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

    Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.

    Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.

  • CVE-2026-0257 · Palo Alto Networks PAN-OSAuthentication Bypass VulnerabilityKnown ransomware usePatch firstAdded to KEV May 29, 2026

    Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

    Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.

    Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

  • CVE-2010-0806 · Microsoft Internet ExplorerUse-After-Free VulnerabilityPatch thirdAdded to KEV May 20, 2026

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Affects anyone running Microsoft Internet Explorer. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.

    Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

  • CVE-2009-3459 · Adobe Acrobat and ReaderHeap-Based Buffer Overflow VulnerabilityPatch thirdAdded to KEV May 20, 2026

    Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

    Affects anyone opening, editing, or signing PDFs in Adobe Acrobat or Reader. For a CPA or legal practice, PDFs are typically client tax returns, engagement letters, signed agreements, and discovery documents — opening a malicious PDF runs attacker code in the user's session, which can pivot to file shares or email.

    Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

  • Microsoft Defender: 2 CVEsPatch thirdadded May 20, 2026
    • Microsoft Defender Link Following Vulnerability

      Affects anyone running Microsoft Defender. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.

      Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

    • Microsoft Defender Denial of Service Vulnerability

      Affects anyone running Microsoft Defender. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.

      Microsoft Defender contains an unspecified vulnerability that allows for denial of service.

  • CVE-2008-4250 · Microsoft WindowsBuffer Overflow VulnerabilityPatch secondAdded to KEV May 20, 2026

    Microsoft Windows Buffer Overflow Vulnerability

    Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.

    Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

Weekly digest

Get the weekly digest in your inbox.

Drop your email and we send you what changed in your watch each week. If nothing changed, we tell you that too.

Watching: the full SMB-relevant list (filter with the chips above to narrow it).

Not sure where to start

You don't have to triage 845 vulnerabilities yourself.

We watch this list daily and tell you which ones touch the software you actually run. Free 30-minute briefing — share what you have, get a prioritized short list back, and we tell you when you don't need us.

Talk with us