Used in ransomware, page 2
As of , 361 vulnerabilities on CISA's list are known to be used in ransomware campaigns.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 101 | CVE-2024-21893Server-Side Request Forgery (SSRF) | Ivanti Connect Secure, Policy Secure, and Neurons | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 102 | CVE-2023-22527Template Injection | Atlassian Confluence Data Center and Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 103 | CVE-2023-29357Privilege Escalation | Microsoft SharePoint Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 104 | CVE-2023-46805Authentication Bypass | Ivanti Connect Secure and Policy Secure | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 105 | CVE-2024-21887Command Injection | Ivanti Connect Secure and Policy Secure | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 106 | CVE-2023-22518Improper Authorization | Atlassian Confluence Data Center and Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 107 | CVE-2023-46604Deserialization of Untrusted Data | Apache ActiveMQ | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 108 | CVE-2023-46747Authentication Bypass | F5 BIG-IP Configuration Utility | Patch this weekRansomware use; Metasploit module; EPSS 0.97 | 0.97 | ||
| 109 | CVE-2023-4966Buffer Overflow | Citrix NetScaler ADC and NetScaler Gateway | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 110 | CVE-2023-22515Broken Access Control | Atlassian Confluence Data Center and Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 111 | CVE-2023-40044Deserialization of Untrusted Data | Progress WS_FTP Server | Patch this weekRansomware use; Metasploit module; EPSS 0.90 | 0.90 | ||
| 112 | CVE-2023-42793Authentication Bypass | JetBrains TeamCity | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 113 | CVE-2021-3129File Upload | Laravel Ignition | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 114 | CVE-2023-38831Code Execution | RARLAB WinRAR | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 115 | CVE-2023-38035Authentication Bypass | Ivanti Sentry | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 116 | CVE-2023-3519Code Injection | Citrix NetScaler ADC and NetScaler Gateway | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 117 | CVE-2023-34362SQL Injection | Progress MOVEit Transfer | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 118 | CVE-2021-45046Deserialization of Untrusted Data | Apache Log4j2 | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 119 | CVE-2023-27350Improper Access Control | PaperCut MF/NG | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 120 | CVE-2021-27877Improper Authentication | Veritas Backup Exec Agent | Patch this weekRansomware use; Metasploit module; EPSS 0.65 | 0.65 | ||
| 121 | CVE-2022-24990Remote Command Execution | TerraMaster TerraMaster OS | Patch this weekRansomware use; Metasploit module; EPSS 0.83 | 0.83 | ||
| 122 | CVE-2023-0669Remote Code Execution | Fortra GoAnywhere MFT | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 123 | CVE-2022-21587Unspecified | Oracle E-Business Suite | Patch this weekRansomware use; Metasploit module; EPSS 0.98 | 0.98 | ||
| 124 | CVE-2022-47966Multiple Products Remote Code Execution | Zoho ManageEngine | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 125 | CVE-2022-41352Arbitrary File Upload | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekRansomware use; Metasploit module; EPSS 0.95 | 0.95 | ||
| 126 | CVE-2022-40684Authentication Bypass | Fortinet Multiple Products | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 127 | CVE-2022-41040Server-Side Request Forgery | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 128 | CVE-2022-41082Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 129 | CVE-2022-26352Unrestricted Upload of File | dotCMS dotCMS | Patch this weekRansomware use; Metasploit module; EPSS 0.91 | 0.91 | ||
| 130 | CVE-2022-27925Arbitrary File Upload | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 131 | CVE-2022-37042Authentication Bypass | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekRansomware use; Metasploit module; EPSS 0.92 | 0.92 | ||
| 132 | CVE-2022-30333Directory Traversal | RARLAB UnRAR | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 133 | CVE-2021-4034Out-of-Bounds Read and Write | Red Hat Polkit | Patch this weekRansomware use; Metasploit module; EPSS 0.94 | 0.94 | ||
| 134 | CVE-2022-30190Support Diagnostic Tool (MSDT) Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 135 | CVE-2019-7192Improper Access Control | QNAP Photo Station | Patch this weekRansomware use; Metasploit module; EPSS 0.88 | 0.88 | ||
| 136 | CVE-2019-7194Path Traversal | QNAP Photo Station | Patch this weekRansomware use; Metasploit module; EPSS 0.83 | 0.83 | ||
| 137 | CVE-2019-7195Path Traversal | QNAP Photo Station | Patch this weekRansomware use; Metasploit module; EPSS 0.90 | 0.90 | ||
| 138 | CVE-2022-26134Confluence Server and Data Center Remote Code Execution | Atlassian Confluence Server/Data Center | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 139 | CVE-2010-1428Information Disclosure | Red Hat JBoss | Patch this weekRansomware use; Metasploit module; EPSS 0.61 | 0.61 | ||
| 140 | CVE-2022-1388Missing Authentication | F5 BIG-IP | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 141 | CVE-2022-29464Unrestrictive Upload of File | WSO2 Multiple Products | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 142 | CVE-2022-22954Server-Side Template Injection | VMware Workspace ONE Access and Identity Manager | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 143 | CVE-2016-0189Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use; Metasploit module; EPSS 0.94 | 0.94 | ||
| 144 | CVE-2021-42237Remote Command Execution | Sitecore XP | Patch this weekRansomware use; Metasploit module; EPSS 0.98 | 0.98 | ||
| 145 | CVE-2020-0796Remote Code Execution | Microsoft SMBv3 | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 146 | CVE-2022-21882Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.59 | 0.59 | ||
| 147 | CVE-2021-21975Server Side Request Forgery in vRealize Operations Manager API | VMware vRealize Operations Manager API | Patch this weekRansomware use; Metasploit module; EPSS 0.78 | 0.78 | ||
| 148 | CVE-2019-1458Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.74 | 0.74 | ||
| 149 | CVE-2017-12149Remote Code Execution | Red Hat JBoss Application Server | Patch this weekRansomware use; Metasploit module; EPSS 0.91 | 0.91 | ||
| 150 | CVE-2021-44228Remote Code Execution | Apache Log4j2 | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 151 | CVE-2021-40449Win32k Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.74 | 0.74 | ||
| 152 | CVE-2021-42321Server Remote Code Execution | Microsoft Exchange | Patch this weekRansomware use; Metasploit module; EPSS 0.92 | 0.92 | ||
| 153 | CVE-2014-1812Group Policy Preferences Password Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.65 | 0.65 | ||
| 154 | CVE-2017-11882Memory Corruption | Microsoft Office | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 155 | CVE-2018-13379SSL VPN Path Traversal | Fortinet FortiOS | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 156 | CVE-2019-11510Arbitrary File Read | Ivanti Pulse Connect Secure | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 157 | CVE-2019-11580Remote Code Execution | Atlassian Crowd and Crowd Data Center | Patch this weekRansomware use; Metasploit module; EPSS 0.95 | 0.95 | ||
| 158 | CVE-2019-18935Deserialization of Untrusted Data | Progress Telerik UI for ASP.NET AJAX | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 159 | CVE-2019-19781ADC, Gateway, and SD-WAN WANOP Appliance Code Execution | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 160 | CVE-2020-1472Privilege Escalation | Microsoft Netlogon | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 161 | CVE-2020-5902Traffic Management User Interface (TMUI) Remote Code Execution | F5 BIG-IP | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 162 | CVE-2021-1675Print Spooler Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.85 | 0.85 | ||
| 163 | CVE-2021-1732Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; Metasploit module; EPSS 0.78 | 0.78 | ||
| 164 | CVE-2021-21972Remote Code Execution | VMware vCenter Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 165 | CVE-2021-21985Improper Input Validation | VMware vCenter Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 166 | CVE-2021-22005File Upload | VMware vCenter Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 167 | CVE-2021-22205Remote Code Execution | GitLab Community and Enterprise Editions | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 168 | CVE-2021-22986iControl REST Remote Code Execution | F5 BIG-IP and BIG-IQ Centralized Management | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 169 | CVE-2021-26084Object-Graph Navigation Language (OGNL) Injection | Atlassian Confluence Server and Data Center | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 170 | CVE-2021-26855Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 171 | CVE-2021-27065Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 172 | CVE-2021-31207Security Feature Bypass | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 173 | CVE-2021-34473Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 174 | CVE-2021-34523Privilege Escalation | Microsoft Exchange Server | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 175 | CVE-2021-34527Print Spooler Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 176 | CVE-2021-35464Core Server Remote Code Execution | ForgeRock Access Management (AM) | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 177 | CVE-2021-36942Local Security Authority (LSA) Spoofing | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.66 | 0.66 | ||
| 178 | CVE-2021-38647Remote Code Execution | Microsoft Open Management Infrastructure (OMI) | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 179 | CVE-2021-40444Remote Code Execution | Microsoft MSHTML | Patch this weekRansomware use; Metasploit module; EPSS 0.97 | 0.97 | ||
| 180 | CVE-2021-40539ADSelfService Plus Authentication Bypass | Zoho ManageEngine | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 181 | CVE-2021-42258SQL Injection | BQE BillQuick Web Suite | Patch this weekRansomware use; Metasploit module; EPSS 0.74 | 0.74 | ||
| 182 | CVE-2023-28252Common Log File System (CLFS) Driver Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module | 0.49 | ||
| 183 | CVE-2020-3153Mobility Client for Windows Uncontrolled Search Path | Cisco AnyConnect Secure | Patch this weekRansomware use; Metasploit module | 0.28 | ||
| 184 | CVE-2022-21999Print Spooler Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module | 0.41 | ||
| 185 | CVE-2020-0787Background Intelligent Transfer Service (BITS) Improper Privilege Management | Microsoft Windows | Patch this weekRansomware use; Metasploit module | 0.43 | ||
| 186 | CVE-2021-27878Command Execution | Veritas Backup Exec Agent | Patch this weekRansomware use; Metasploit module | 0.24 | ||
| 187 | CVE-2018-8440Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; Metasploit module | 0.18 | ||
| 188 | CVE-2021-27876File Access | Veritas Backup Exec Agent | Patch this weekRansomware use; Metasploit module | 0.14 | ||
| 189 | CVE-2020-3433Mobility Client for Windows DLL Hijacking | Cisco AnyConnect Secure | Patch this weekRansomware use; Metasploit module | 0.10 | ||
| 190 | CVE-2018-7602Remote Code Execution | Drupal Core | Patch this weekRansomware use; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| 191 | CVE-2016-0151Windows CSRSS Security Feature Bypass | Microsoft Client-Server Run-time Subsystem (CSRSS) | Patch this weekRansomware use; EPSS 0.63; verified Exploit-DB entry | 0.63 | ||
| 192 | CVE-2017-0213Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; EPSS 0.84; verified Exploit-DB entry | 0.84 | ||
| 193 | CVE-2015-7645Arbitrary Code Execution | Adobe Flash Player | Patch this weekRansomware use; EPSS 0.65; verified Exploit-DB entry | 0.65 | ||
| 194 | CVE-2018-13374Improper Access Control | Fortinet FortiOS and FortiADC | Patch this weekRansomware use; verified Exploit-DB entry | 0.38 | ||
| 195 | CVE-2019-0543Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; verified Exploit-DB entry | 0.05 | ||
| 196 | CVE-2025-10035Deserialization of Untrusted Data | Fortra GoAnywhere MFT | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 197 | CVE-2025-8088Path Traversal | RARLAB WinRAR | Patch this weekRansomware use; EPSS 0.94 | 0.94 | ||
| 198 | CVE-2025-5777Out-of-Bounds Read | Citrix NetScaler ADC and Gateway | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 199 | CVE-2025-31324Unrestricted File Upload | SAP NetWeaver | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 200 | CVE-2025-31161Authentication Bypass | CrushFTP CrushFTP | Patch this weekRansomware use; EPSS 0.99 | 0.99 |