Used in ransomware, page 3
As of , 361 vulnerabilities on CISA's list are known to be used in ransomware campaigns.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 201 | CVE-2024-53704SSLVPN Improper Authentication | SonicWall SonicOS | Patch this weekRansomware use; EPSS 0.95 | 0.95 | ||
| 202 | CVE-2024-55591Authentication Bypass | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use; EPSS 0.94 | 0.94 | ||
| 203 | CVE-2025-0282Stack-Based Buffer Overflow | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 204 | CVE-2024-41713Path Traversal | Mitel MiCollab | Patch this weekRansomware use; EPSS 0.98 | 0.98 | ||
| 205 | CVE-2024-50623Unrestricted File Upload | Cleo Multiple Products | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 206 | CVE-2023-28461AG and vxAG ArrayOS Missing Authentication for Critical Function | Array Networks AG/vxAG ArrayOS | Patch this weekRansomware use; EPSS 0.68 | 0.68 | ||
| 207 | CVE-2024-40711Backup and Replication Deserialization | Veeam Backup & Replication | Patch this weekRansomware use; EPSS 0.90 | 0.90 | ||
| 208 | CVE-2024-30088Kernel TOCTOU Race Condition | Microsoft Windows | Patch this weekRansomware use; EPSS 0.68 | 0.68 | ||
| 209 | CVE-2024-21338Kernel Exposed IOCTL with Insufficient Access Control | Microsoft Windows | Patch this weekRansomware use; EPSS 0.60 | 0.60 | ||
| 210 | CVE-2020-3259ASA and FTD Information Disclosure | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch this weekRansomware use; EPSS 0.72 | 0.72 | ||
| 211 | CVE-2024-21412Internet Shortcut Files Security Feature Bypass | Microsoft Windows | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 212 | CVE-2024-21762Out-of-Bound Write | Fortinet FortiOS | Patch this weekRansomware use; EPSS 0.83 | 0.83 | ||
| 213 | CVE-2023-35082Authentication Bypass | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 214 | CVE-2023-29300Deserialization of Untrusted Data | Adobe ColdFusion | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 215 | CVE-2023-38203Deserialization of Untrusted Data | Adobe ColdFusion | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| 216 | CVE-2023-41265HTTP Tunneling | Qlik Sense | Patch this weekRansomware use; EPSS 0.88 | 0.88 | ||
| 217 | CVE-2023-41266Path Traversal | Qlik Sense | Patch this weekRansomware use; EPSS 0.85 | 0.85 | ||
| 218 | CVE-2023-47246Path Traversal | SysAid SysAid Server | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 219 | CVE-2023-27532Cloud Connect Missing Authentication for Critical Function | Veeam Backup & Replication | Patch this weekRansomware use; EPSS 0.81 | 0.81 | ||
| 220 | CVE-2023-35078Endpoint Manager Mobile Authentication Bypass | Ivanti Endpoint Manager Mobile (EPMM) | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 221 | CVE-2023-36884Search Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 222 | CVE-2023-27997Heap-Based Buffer Overflow | Fortinet FortiOS and FortiProxy SSL-VPN | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| 223 | CVE-2023-24880SmartScreen Security Feature Bypass | Microsoft Windows | Patch this weekRansomware use; EPSS 0.78 | 0.78 | ||
| 224 | CVE-2022-36537Unspecified | ZK Framework AuUploader | Patch this weekRansomware use; EPSS 0.95 | 0.95 | ||
| 225 | CVE-2022-47986Code Execution | IBM Aspera Faspex | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 226 | CVE-2017-11357UI for ASP.NET AJAX Insecure Direct Object Reference | Telerik User Interface (UI) for ASP.NET AJAX | Patch this weekRansomware use; EPSS 0.78 | 0.78 | ||
| 227 | CVE-2022-41080Privilege Escalation | Microsoft Exchange Server | Patch this weekRansomware use; EPSS 0.77 | 0.77 | ||
| 228 | CVE-2022-42475Heap-Based Buffer Overflow | Fortinet FortiOS | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 229 | CVE-2022-44698SmartScreen Security Feature Bypass | Microsoft Defender | Patch this weekRansomware use; EPSS 0.76 | 0.76 | ||
| 230 | CVE-2018-6530OS Command Injection | D-Link Multiple Routers | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| 231 | CVE-2022-27593Externally Controlled Reference | QNAP Photo Station | Patch this weekRansomware use; EPSS 0.88 | 0.88 | ||
| 232 | CVE-2022-2294Heap Buffer Overflow | WebRTC WebRTC | Patch this weekRansomware use; EPSS 0.70 | 0.70 | ||
| 233 | CVE-2022-27924Command Injection | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekRansomware use; EPSS 0.94 | 0.94 | ||
| 234 | CVE-2022-29499Data Validation | Mitel MiVoice Connect | Patch this weekRansomware use; EPSS 0.55 | 0.55 | ||
| 235 | CVE-2016-0034Runtime Remote Code Execution | Microsoft Silverlight | Patch this weekRansomware use; EPSS 0.69 | 0.69 | ||
| 236 | CVE-2017-18362VSA SQL Injection | Kaseya Virtual System/Server Administrator (VSA) | Patch this weekRansomware use; EPSS 0.87 | 0.87 | ||
| 237 | CVE-2019-16057DNS-320 Remote Code Execution | D-Link DNS-320 Storage Device | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| 238 | CVE-2021-42278Domain Services Privilege Escalation | Microsoft Active Directory | Patch this weekRansomware use; EPSS 0.73 | 0.73 | ||
| 239 | CVE-2021-42287Domain Services Privilege Escalation | Microsoft Active Directory | Patch this weekRansomware use; EPSS 0.77 | 0.77 | ||
| 240 | CVE-2018-10562GPON Routers Command Injection | Dasan Gigabit Passive Optical Network (GPON) Routers | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 241 | CVE-2021-28799NAS Improper Authorization | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use; EPSS 0.78 | 0.78 | ||
| 242 | CVE-2021-26085Pre-Authorization Arbitrary File Read | Atlassian Confluence Server | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 243 | CVE-2017-12615on Windows Remote Code Execution | Apache Tomcat | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 244 | CVE-2018-1273Property Binder | VMware Tanzu Spring Data Commons | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| 245 | CVE-2017-0101Transaction Manager Privilege Escalation | Microsoft Windows | Patch this weekRansomware use; EPSS 0.57 | 0.57 | ||
| 246 | CVE-2018-8174VBScript Engine Out-of-Bounds Write | Microsoft Windows | Patch this weekRansomware use; EPSS 0.88 | 0.88 | ||
| 247 | CVE-2018-15982Use-After-Free | Adobe Flash Player | Patch this weekRansomware use; EPSS 0.90 | 0.90 | ||
| 248 | CVE-2019-0752Type Confusion | Microsoft Internet Explorer | Patch this weekRansomware use; EPSS 0.82 | 0.82 | ||
| 249 | CVE-2021-20038Stack-Based Buffer Overflow | SonicWall SMA 100 Appliances | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 250 | CVE-2018-13382Improper Authorization | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use; EPSS 0.82 | 0.82 | ||
| 251 | CVE-2021-40438HTTP Server-Side Request Forgery (SSRF) | Apache Apache | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 252 | CVE-2016-7255Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use; EPSS 0.81 | 0.81 | ||
| 253 | CVE-2018-0802Memory Corruption | Microsoft Office | Patch this weekRansomware use; EPSS 0.93 | 0.93 | ||
| 254 | CVE-2018-4878Use-After-Free | Adobe Flash Player | Patch this weekRansomware use; EPSS 0.90 | 0.90 | ||
| 255 | CVE-2018-6789Buffer Overflow | Exim Exim | Patch this weekRansomware use; EPSS 0.82 | 0.82 | ||
| 256 | CVE-2019-0604Remote Code Execution | Microsoft SharePoint | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 257 | CVE-2019-5544OpenSLP Heap-Based Buffer Overflow | VMware VMware ESXi and Horizon DaaS | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| 258 | CVE-2019-7481SQL Injection | SonicWall SMA100 | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 259 | CVE-2020-3580ASA and FTD Cross-Site Scripting (XSS) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| 260 | CVE-2020-3992OpenSLP Use-After-Free | VMware ESXi | Patch this weekRansomware use; EPSS 0.83 | 0.83 | ||
| 261 | CVE-2021-20021Improper Privilege Management | SonicWall SonicWall Email Security | Patch this weekRansomware use; EPSS 0.89 | 0.89 | ||
| 262 | CVE-2021-26411Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use; EPSS 0.81 | 0.81 | ||
| 263 | CVE-2021-26857Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; EPSS 0.96 | 0.96 | ||
| 264 | CVE-2021-26858Remote Code Execution | Microsoft Exchange Server | Patch this weekRansomware use; EPSS 0.94 | 0.94 | ||
| 265 | CVE-2021-27104OS Command Injection | Accellion FTA | Patch this weekRansomware use; EPSS 0.57 | 0.57 | ||
| 266 | CVE-2021-30116Information Disclosure | Kaseya Virtual System/Server Administrator (VSA) | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| 267 | CVE-2021-35211Remote Code Execution | SolarWinds Serv-U | Patch this weekRansomware use; EPSS 0.91 | 0.91 | ||
| 268 | CVE-2025-26633Management Console (MMC) Improper Neutralization | Microsoft Windows | Patch this weekRansomware use | 0.30 | ||
| 269 | CVE-2023-48365HTTP Tunneling | Qlik Sense | Patch this weekRansomware use | 0.47 | ||
| 270 | CVE-2024-55550Path Traversal | Mitel MiCollab | Patch this weekRansomware use | 0.38 | ||
| 271 | CVE-2024-38094Deserialization | Microsoft SharePoint | Patch this weekRansomware use; EPSS 0.51 | 0.51 | ||
| 272 | CVE-2024-1086Use-After-Free | Linux Kernel | Patch this weekRansomware use | 0.28 | ||
| 273 | CVE-2017-6884Command Injection | Zyxel EMG2926 Routers | Patch this weekRansomware use | 0.35 | ||
| 274 | CVE-2022-31199Insecure Object Deserialization | Netwrix Auditor | Patch this weekRansomware use | 0.36 | ||
| 275 | CVE-2022-37969Common Log File System (CLFS) Driver Privilege Escalation | Microsoft Windows | Patch this weekRansomware use | 0.28 | ||
| 276 | CVE-2018-19949NAS File Station Command Injection | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.28 | ||
| 277 | CVE-2018-19953NAS File Station Cross-Site Scripting | QNAP Network Attached Storage (NAS) | Patch this weekRansomware use | 0.29 | ||
| 278 | CVE-2018-6882Cross-Site Scripting (XSS) | Synacor Zimbra Collaboration Suite (ZCS) | Patch this weekRansomware use | 0.30 | ||
| 279 | CVE-2018-20753VSA Remote Code Execution | Kaseya Virtual System/Server Administrator (VSA) | Patch this weekRansomware use | 0.29 | ||
| 280 | CVE-2021-20028SQL Injection | SonicWall Secure Remote Access (SRA) | Patch this weekRansomware use | 0.30 | ||
| 281 | CVE-2021-22941Improper Access Control | Citrix ShareFile | Patch this weekRansomware use; EPSS 0.54 | 0.54 | ||
| 282 | CVE-2018-8581Privilege Escalation | Microsoft Exchange Server | Patch this weekRansomware use | 0.27 | ||
| 283 | CVE-2022-24682Cross-Site Scripting | Synacor Zimbra Collaborate Suite (ZCS) | Patch this weekRansomware use | 0.31 | ||
| 284 | CVE-2018-13383Out-of-bounds Write | Fortinet FortiOS and FortiProxy | Patch this weekRansomware use | 0.34 | ||
| 285 | CVE-2019-1579Remote Code Execution | Palo Alto Networks PAN-OS | Patch this weekRansomware use | 0.46 | ||
| 286 | CVE-2018-2380Path Traversal | SAP Customer Relationship Management (CRM) | Patch this weekRansomware use | 0.29 | ||
| 287 | CVE-2019-0803Privilege Escalation | Microsoft Win32k | Patch this weekRansomware use | 0.45 | ||
| 288 | CVE-2019-1367Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use; EPSS 0.52 | 0.52 | ||
| 289 | CVE-2019-13608XML External Entity (XXE) Processing | Citrix StoreFront Server | Patch this weekRansomware use | 0.30 | ||
| 290 | CVE-2020-0968Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use | 0.31 | ||
| 291 | CVE-2020-12271SQL Injection | Sophos SFOS | Patch this weekRansomware use | 0.42 | ||
| 292 | CVE-2020-12812SSL VPN Improper Authentication | Fortinet FortiOS | Patch this weekRansomware use | 0.45 | ||
| 293 | CVE-2021-20016SQL Injection | SonicWall SSLVPN SMA100 | Patch this weekRansomware use | 0.40 | ||
| 294 | CVE-2021-20023Path Traversal | SonicWall SonicWall Email Security | Patch this weekRansomware use; EPSS 0.52 | 0.52 | ||
| 295 | CVE-2021-22893Use-After-Free | Ivanti Pulse Connect Secure | Patch this weekRansomware use | 0.47 | ||
| 296 | CVE-2018-8639Win32k Improper Resource Shutdown or Release | Microsoft Windows | Patch this weekRansomware use | 0.22 | ||
| 297 | CVE-2025-23006Deserialization | SonicWall SMA1000 Appliances | Patch this weekRansomware use | 0.23 | ||
| 298 | CVE-2024-9680Use-After-Free | Mozilla Firefox | Patch this weekRansomware use | 0.23 | ||
| 299 | CVE-2024-40766Improper Access Control | SonicWall SonicOS | Patch this weekRansomware use | 0.18 | ||
| 300 | CVE-2024-37085Authentication Bypass | VMware ESXi | Patch this weekRansomware use | 0.27 |