Cyber Risk Directory
Public-source intelligence across vulnerabilities, ransomware activity, industries and countries. Updated continuously.
Top known-exploited vulnerabilities (1,661 tracked)
| CVE | Name | EPSS | Ransomware |
|---|---|---|---|
| CVE-2021-26086 | Atlassian Jira Server and Data Center Path Traversal Vulnerability | 100.0% | No |
| CVE-2024-23897 | Jenkins Command Line Interface (CLI) Path Traversal Vulnerability | 100.0% | Yes |
| CVE-2024-3400 | Palo Alto Networks PAN-OS Command Injection Vulnerability | 100.0% | Yes |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request | 100.0% | Yes |
| CVE-2023-35082 | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authenticati | 100.0% | Yes |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure Command Injection Vulnerabilit | 100.0% | Yes |
| CVE-2023-1671 | Sophos Web Appliance Command Injection Vulnerability | 100.0% | No |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server Improper Authorization Vul | 100.0% | Yes |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerabili | 100.0% | Yes |
| CVE-2023-44487 | HTTP/2 Rapid Reset Attack Vulnerability | 100.0% | No |
| CVE-2023-32315 | Ignite Realtime Openfire Path Traversal Vulnerability | 100.0% | No |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability | 100.0% | Yes |
| CVE-2023-1389 | TP-Link Archer AX-21 Command Injection Vulnerability | 100.0% | No |
| CVE-2023-27350 | PaperCut MF/NG Improper Access Control Vulnerability | 100.0% | Yes |
| CVE-2023-0669 | Fortra GoAnywhere MFT Remote Code Execution Vulnerability | 100.0% | Yes |
Ransomware groups
clop (41)
thegentlemen (35)
Orova (24)
qilin (23)
everest (17)
Dark Project (16)
orion (14)
incransom (11)
CRPxO (11)
lockbit5 (10)
safepay (9)
krybit (7)
dragonforce (7)
play (5)
coinbasecartel (4)
Gammax (3)
anubis (3)
genesis (3)
akira (3)
shinyhunters (3)
Global Secret Group (2)
aurora (2)
Panzer (2)
insomnia (2)
cmdorganization (2)
chaos (2)
securotrop (1)
gunra (1)
pear (1)
ransomhouse (1)
Company security profiles (259 analyzed)
Cyber Exposure Scores computed from public signals — email authentication, DNS, TLS, internet exposure and breach history. Newly analyzed domains appear here automatically.
Country risk profiles
Industry risk profiles
Is your domain exposed?
Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.
Get your free reportAll information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.