Skip to content

Reverse lookup

Exploited vulnerabilities

NVD tells you what a vulnerability is. It doesn't tell you that APT28 burned CVE-2023-23397 as a zero-day for eleven months before patch, or that six unrelated groups adopted Log4Shell within a fortnight of disclosure. Adoption pattern is the analytically useful part — so that's what this leads with.

47

CVEs with attributed exploitation

22

Exploited by more than one actor

12

Used as a zero-day by someone

47

On the CISA KEV catalog

FilterSort

47 of 47 vulnerabilities

  • KEVransomware
    21 Feb 20242 actors

    ConnectWise · ConnectWise ScreenConnect

    ConnectWise ScreenConnect authentication bypass via path traversal in the setup wizard. Trivially exploitable — appending a path segment grants administrator account creation.

  • KEVransomware
    5 Mar 20192 actors

    Microsoft · Microsoft SharePoint

    Microsoft SharePoint XML deserialisation remote code execution. Heavily used against government SharePoint deployments through 2019–2020.

  • KEVransomware0-day · Lazarus Group, APT37
    6 Feb 20182 actors

    Adobe · Adobe Flash Player

    Adobe Flash Player use-after-free in the DRM component. Exploited as a zero-day against South Korean targets before patch.

  • KEVransomware
    10 Oct 20232 actors

    Citrix · Citrix NetScaler

    Citrix NetScaler sensitive information disclosure ('CitrixBleed'). Leaks session tokens from process memory, allowing full MFA bypass by replaying a hijacked session.

  • KEVransomware
    11 Feb 20202 actors

    Microsoft · Microsoft Exchange Server

    Microsoft Exchange Server validation key remote code execution. Exchange installations shipped a static cryptographic key, letting any authenticated user forge a ViewState payload and execute as SYSTEM.

  • KEV
    10 Apr 20122 actors

    Microsoft · Microsoft Office

    Microsoft Windows Common Controls (MSCOMCTL.OCX) buffer overflow. The defining document exploit of the early APT era — used by nearly every Chinese and Russian espionage group between 2012 and 2016.

  • KEVransomware
    16 Mar 20172 actors

    Microsoft · Windows SMBv1

    Windows SMBv1 remote code execution ('EternalBlue'). Originally an NSA capability leaked by the Shadow Brokers in April 2017; weaponised within weeks into WannaCry and NotPetya.

  • KEVransomware0-day · Silk Typhoon
    2 Mar 20212 actors

    Microsoft · Microsoft Exchange Server

    Microsoft Exchange Server post-authentication arbitrary file write. Second half of the ProxyLogon chain — writes a web shell to an IIS-accessible path.

  • KEVransomware
    12 Apr 20241 actor

    Palo Alto Networks · PAN-OS GlobalProtect

    Palo Alto PAN-OS GlobalProtect command injection. An unauthenticated attacker executes arbitrary code as root on the firewall via a crafted session cookie.

  • KEV
    16 Oct 20231 actor

    Cisco · Cisco IOS XE

    Cisco IOS XE web UI privilege escalation. An unauthenticated attacker creates a level-15 local account on an internet-exposed device — effectively a backdoor by design flaw. Over 40,000 devices were implanted within days.

  • KEVransomware0-day · Cl0p
    27 Oct 20241 actor

    Cleo · Cleo Harmony / VLTrader

    Cleo Harmony / VLTrader / LexiCom unrestricted file upload enabling remote code execution. Exploited for mass data theft against managed file transfer deployments in late 2024.

    Cl0p0d
  • KEV
    14 Dec 20231 actor

    Unitronics · Unitronics Vision PLC

    Unitronics Vision series PLCs ship with a default administrative password. Not a memory-safety bug — an internet-exposed default credential on equipment controlling physical processes.

  • KEVransomware
    19 Jul 20231 actor

    Citrix · Citrix NetScaler

    Citrix NetScaler ADC / Gateway unauthenticated stack overflow enabling remote code execution. Exploited as a zero-day against a U.S. critical infrastructure organisation.

  • KEVransomware
    13 Jun 20231 actor

    Fortinet · FortiOS SSL VPN

    FortiOS/FortiProxy SSL-VPN heap overflow ('XORtigate') reachable pre-authentication.

  • KEVransomware0-day · Cl0p
    2 Jun 20231 actor

    Progress Software · MOVEit Transfer

    Progress MOVEit Transfer SQL injection enabling remote code execution and mass data theft. Cl0p's exploitation affected an estimated 2,700+ organisations and 95 million individuals.

    Cl0p0d
  • KEVransomware
    20 Apr 20231 actor

    PaperCut · PaperCut MF / NG

    PaperCut MF/NG improper access control enabling unauthenticated remote code execution.

    LockBit
  • KEV0-day · APT28
    14 Mar 20231 actor

    Microsoft · Microsoft Outlook

    Microsoft Outlook elevation of privilege. A crafted appointment with a UNC path in the reminder sound property forces Outlook to authenticate to an attacker-controlled SMB server, leaking the Net-NTLMv2 hash with zero user interaction — the message does not need to be opened.

    APT280d
  • KEVransomware
    12 Dec 20221 actor

    Fortinet · FortiOS SSL VPN

    FortiOS SSL-VPN heap buffer overflow permitting unauthenticated remote code execution. Exploited as a zero-day against government targets.

  • KEVransomware
    3 Jun 20221 actor

    Atlassian · Confluence Server / Data Center

    Atlassian Confluence OGNL injection enabling unauthenticated remote code execution.

    APT40
  • KEVransomware
    5 May 20221 actor

    F5 · F5 BIG-IP

    F5 BIG-IP iControl REST authentication bypass permitting arbitrary command execution as root.

  • KEVransomware
    24 Feb 20211 actor

    VMware · VMware vCenter Server

    VMware vCenter Server vSphere Client plugin unauthenticated remote code execution.

    APT29
  • KEVransomware
    21 Oct 20201 actor

    Oracle · Oracle WebLogic Server

    Oracle WebLogic Server console remote code execution via authentication bypass.

    APT41
  • KEVransomware
    9 Dec 20191 actor

    Progress Software · Telerik UI for ASP.NET AJAX

    Progress Telerik UI for ASP.NET AJAX insecure deserialisation enabling remote code execution.

    APT41
  • KEVransomware
    16 May 20191 actor

    Microsoft · Windows RDP

    Windows Remote Desktop Services remote code execution ('BlueKeep'). Pre-authentication and wormable; prompted an out-of-band patch for end-of-life Windows XP.

    Andariel
  • KEV
    28 Mar 20181 actor

    Cisco · Cisco IOS / IOS XE

    Cisco Smart Install remote code execution. Smart Install is enabled by default and unauthenticated; large numbers of edge routers remain exposed years later.

  • KEVransomware
    12 Jan 20241 actor

    Ivanti · Ivanti Connect Secure

    Ivanti Connect Secure command injection in web components, exploitable as an authenticated administrator or unauthenticated when chained with CVE-2023-46805.

  • KEVransomware0-day · Silk Typhoon
    8 Jan 20251 actor

    Ivanti · Ivanti Connect Secure

    Ivanti Connect Secure stack-based buffer overflow allowing unauthenticated remote code execution. Exploited as a zero-day by a China-nexus cluster from December 2024.

  • KEVransomware0-day · Lazarus Group
    13 Feb 20241 actor

    Microsoft · Windows SmartScreen

    Windows Internet Shortcut Files security feature bypass. A crafted .url file evades SmartScreen prompting, delivering payloads without the Mark-of-the-Web warning.

  • KEV0-day · APT28
    11 Oct 20221 actor

    Microsoft · Windows Print Spooler

    Windows Print Spooler elevation of privilege, exploited as a zero-day with the GooseEgg tool to escalate and steal credentials.

    APT280d
  • KEVransomware0-day · FIN7
    12 Apr 20161 actor

    Microsoft · Windows Win32k

    Microsoft Win32k elevation of privilege, exploited as a zero-day in targeted financial-sector intrusions.

    FIN70d
  • KEV
    8 Sep 20151 actor

    Microsoft · Microsoft Office

    Microsoft Office EPS filter remote code execution via a malformed PostScript image. A staple of Chinese and Korean-peninsula espionage phishing in 2015–2017.

    APT28
  • KEV0-day · Sandworm
    15 Oct 20141 actor

    Microsoft · Microsoft Windows OLE

    Windows OLE package manager remote code execution ('Sandworm'). A PowerPoint file fetches and executes a remote INF-referenced payload. Its discovery gave the Sandworm group its name.

    Sandworm0d
  • KEVransomware0-day · Cl0p
    6 Feb 20231 actor

    Fortra · GoAnywhere MFT

    Fortra GoAnywhere MFT pre-authentication command injection via deserialisation in the licence response servlet.

    Cl0p0d