Microsoft · Microsoft Office
Microsoft Office Equation Editor stack buffer overflow. A seventeen-year-old component compiled without modern mitigations; remained one of the most-used exploits in phishing for years after patch.
Reverse lookup
NVD tells you what a vulnerability is. It doesn't tell you that APT28 burned CVE-2023-23397 as a zero-day for eleven months before patch, or that six unrelated groups adopted Log4Shell within a fortnight of disclosure. Adoption pattern is the analytically useful part — so that's what this leads with.
47
CVEs with attributed exploitation
22
Exploited by more than one actor
12
Used as a zero-day by someone
47
On the CISA KEV catalog
47 of 47 vulnerabilities
Microsoft · Microsoft Office
Microsoft Office Equation Editor stack buffer overflow. A seventeen-year-old component compiled without modern mitigations; remained one of the most-used exploits in phishing for years after patch.
Microsoft · Microsoft Office
Microsoft Office / WordPad remote code execution via a crafted OLE2link object that silently fetches and runs an HTA payload.
Apache · Apache Log4j2
Apache Log4j2 JNDI remote code execution ('Log4Shell'). Any logged attacker-controlled string triggers a remote class load. The most consequential vulnerability of the decade by breadth of exposure — present in effectively every enterprise Java estate.
Microsoft · Microsoft Exchange Server
Microsoft Exchange Server SSRF ('ProxyLogon'). Allows an unauthenticated attacker to send arbitrary HTTP requests and authenticate as the Exchange server; chained with CVE-2021-27065 for authenticated file write and full RCE.
Microsoft · Windows Netlogon
Netlogon elevation of privilege ('Zerologon'). A cryptographic flaw in the AES-CFB8 initialisation of Netlogon lets an unauthenticated attacker on the network set the domain controller's machine account password to empty, yielding instant domain admin.
Fortinet · FortiOS SSL VPN
Fortinet FortiOS SSL VPN path traversal. Allows unauthenticated retrieval of the session file containing plaintext credentials. Still being exploited years after patch because harvested credentials were never rotated.
JetBrains · JetBrains TeamCity
JetBrains TeamCity authentication bypass leading to remote code execution. Compromise of a CI server yields signing keys and source, making it a high-value supply-chain foothold.
Citrix · Citrix ADC / Gateway
Citrix ADC / Gateway directory traversal leading to unauthenticated remote code execution. Roughly 80,000 internet-facing appliances were vulnerable at disclosure.
Ivanti / Pulse Secure · Pulse Connect Secure
Pulse Connect Secure arbitrary file read. Yields plaintext credentials and session tokens from the appliance without authentication.
Zoho · Zoho ManageEngine
Zoho ManageEngine unauthenticated remote code execution via an outdated Apache Santuario XML signature library.
Microsoft · Microsoft Exchange Server
Microsoft Exchange Server RCE ('ProxyShell'). Pre-authentication path confusion in the Autodiscover front end, chained with CVE-2021-34523 and CVE-2021-31207 to reach arbitrary code execution as SYSTEM.
RARLAB · WinRAR
RARLAB WinRAR spoofing vulnerability. A crafted archive displays a benign file while executing a same-named script from a shadow directory when the decoy is opened.
Microsoft · Microsoft Windows MSDT
Microsoft Support Diagnostic Tool remote code execution ('Follina'). A Word document referencing the ms-msdt: URI protocol executes PowerShell without macros — bypassing the macro-blocking controls organisations had just deployed.
ConnectWise · ConnectWise ScreenConnect
ConnectWise ScreenConnect authentication bypass via path traversal in the setup wizard. Trivially exploitable — appending a path segment grants administrator account creation.
Microsoft · Microsoft SharePoint
Microsoft SharePoint XML deserialisation remote code execution. Heavily used against government SharePoint deployments through 2019–2020.
Adobe · Adobe Flash Player
Adobe Flash Player use-after-free in the DRM component. Exploited as a zero-day against South Korean targets before patch.
Citrix · Citrix NetScaler
Citrix NetScaler sensitive information disclosure ('CitrixBleed'). Leaks session tokens from process memory, allowing full MFA bypass by replaying a hijacked session.
Microsoft · Microsoft Exchange Server
Microsoft Exchange Server validation key remote code execution. Exchange installations shipped a static cryptographic key, letting any authenticated user forge a ViewState payload and execute as SYSTEM.
Microsoft · Microsoft Office
Microsoft Windows Common Controls (MSCOMCTL.OCX) buffer overflow. The defining document exploit of the early APT era — used by nearly every Chinese and Russian espionage group between 2012 and 2016.
Ivanti · Ivanti Connect Secure
Ivanti Connect Secure authentication bypass in the web component. Chained with CVE-2024-21887 for unauthenticated remote code execution.
Microsoft · Windows SMBv1
Windows SMBv1 remote code execution ('EternalBlue'). Originally an NSA capability leaked by the Shadow Brokers in April 2017; weaponised within weeks into WannaCry and NotPetya.
Microsoft · Microsoft Exchange Server
Microsoft Exchange Server post-authentication arbitrary file write. Second half of the ProxyLogon chain — writes a web shell to an IIS-accessible path.
Palo Alto Networks · PAN-OS GlobalProtect
Palo Alto PAN-OS GlobalProtect command injection. An unauthenticated attacker executes arbitrary code as root on the firewall via a crafted session cookie.
Cisco · Cisco IOS XE
Cisco IOS XE web UI privilege escalation. An unauthenticated attacker creates a level-15 local account on an internet-exposed device — effectively a backdoor by design flaw. Over 40,000 devices were implanted within days.
Cleo · Cleo Harmony / VLTrader
Cleo Harmony / VLTrader / LexiCom unrestricted file upload enabling remote code execution. Exploited for mass data theft against managed file transfer deployments in late 2024.
Unitronics · Unitronics Vision PLC
Unitronics Vision series PLCs ship with a default administrative password. Not a memory-safety bug — an internet-exposed default credential on equipment controlling physical processes.
Citrix · Citrix NetScaler
Citrix NetScaler ADC / Gateway unauthenticated stack overflow enabling remote code execution. Exploited as a zero-day against a U.S. critical infrastructure organisation.
Fortinet · FortiOS SSL VPN
FortiOS/FortiProxy SSL-VPN heap overflow ('XORtigate') reachable pre-authentication.
Progress Software · MOVEit Transfer
Progress MOVEit Transfer SQL injection enabling remote code execution and mass data theft. Cl0p's exploitation affected an estimated 2,700+ organisations and 95 million individuals.
PaperCut · PaperCut MF / NG
PaperCut MF/NG improper access control enabling unauthenticated remote code execution.
Microsoft · Microsoft Outlook
Microsoft Outlook elevation of privilege. A crafted appointment with a UNC path in the reminder sound property forces Outlook to authenticate to an attacker-controlled SMB server, leaking the Net-NTLMv2 hash with zero user interaction — the message does not need to be opened.
Fortinet · FortiOS SSL VPN
FortiOS SSL-VPN heap buffer overflow permitting unauthenticated remote code execution. Exploited as a zero-day against government targets.
Atlassian · Confluence Server / Data Center
Atlassian Confluence OGNL injection enabling unauthenticated remote code execution.
F5 · F5 BIG-IP
F5 BIG-IP iControl REST authentication bypass permitting arbitrary command execution as root.
VMware · VMware vCenter Server
VMware vCenter Server vSphere Client plugin unauthenticated remote code execution.
Oracle · Oracle WebLogic Server
Oracle WebLogic Server console remote code execution via authentication bypass.
Progress Software · Telerik UI for ASP.NET AJAX
Progress Telerik UI for ASP.NET AJAX insecure deserialisation enabling remote code execution.
Microsoft · Windows RDP
Windows Remote Desktop Services remote code execution ('BlueKeep'). Pre-authentication and wormable; prompted an out-of-band patch for end-of-life Windows XP.
Cisco · Cisco IOS / IOS XE
Cisco Smart Install remote code execution. Smart Install is enabled by default and unauthenticated; large numbers of edge routers remain exposed years later.
Ivanti · Ivanti Connect Secure
Ivanti Connect Secure command injection in web components, exploitable as an authenticated administrator or unauthenticated when chained with CVE-2023-46805.
Ivanti · Ivanti Connect Secure
Ivanti Connect Secure stack-based buffer overflow allowing unauthenticated remote code execution. Exploited as a zero-day by a China-nexus cluster from December 2024.
Microsoft · Windows SmartScreen
Windows Internet Shortcut Files security feature bypass. A crafted .url file evades SmartScreen prompting, delivering payloads without the Mark-of-the-Web warning.
Microsoft · Windows Print Spooler
Windows Print Spooler elevation of privilege, exploited as a zero-day with the GooseEgg tool to escalate and steal credentials.
Microsoft · Windows Win32k
Microsoft Win32k elevation of privilege, exploited as a zero-day in targeted financial-sector intrusions.
Microsoft · Microsoft Office
Microsoft Office EPS filter remote code execution via a malformed PostScript image. A staple of Chinese and Korean-peninsula espionage phishing in 2015–2017.
Microsoft · Microsoft Windows OLE
Windows OLE package manager remote code execution ('Sandworm'). A PowerPoint file fetches and executes a remote INF-referenced payload. Its discovery gave the Sandworm group its name.
Fortra · GoAnywhere MFT
Fortra GoAnywhere MFT pre-authentication command injection via deserialisation in the licence response servlet.