Hazard · updated today
Two questions, answered with evidence.
Which vulnerabilities are attackers actually using — and what it has cost UK organisations when the answer was ignored. Both halves are built from public data, updated daily, and free to use.
Running Fortinet, Ivanti or Exchange? Build a watchlist and see only what is being exploited in your stack — no account, nothing stored.
1,685
vulnerabilities confirmed exploited
352
used in ransomware campaigns
222
UK enforcement actions on record
£53.48m
in penalties issued
Newly confirmed exploited
All 1,685 →- CVE-2023-49105 ownCloud Improper Authentication Vulnerability ownCloud · ownCloud
- CVE-2026-53362 Linux Kernel Unspecified Vulnerability Linux · Kernel
- CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability JFrog · Artifactory
- CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability Ajax.NET Professional · Ajax.NET Professional
- CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability Red Hat · Libuser
- CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability Red Hat · Automatic Bug Reporting Tool
- CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability Linux · Kernel
- CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability Citrix · NetScaler ADC and NetScaler Gateway
Latest UK enforcement
All 222 →- ACRO Criminal Records Office The Information Commissioner (the Commissioner) issues a reprimand to ACRO Criminal Records Office for infringements of Articles 3…
- Elderly Aids Limited Contravention of Regulations 21 and 24. Elderly Aids Limited promoted call blocking devices. Elderly Aids Limited made 758,053 uns…
- Elderly Aids Limited Contravention of Regulations 21 and 24. Elderly Aids Limited promoted call blocking devices. Elderly Aids Limited made 758,053 uns…
- Chief Constable Commissioner for the Metropolis/ Metropolitan Police Service (MPS) Incident 1 (ICO Ref: INV/0034/2025), concerning the service of unredacted documents in support of a Stalking Protection Order appl…
- Chief Constable Commissioner for the Metropolis/ Metropolitan Police Service (MPS) Incident 1 (ICO Ref: INV/0034/2025), concerning the service of unredacted documents in support of a Stalking Protection Order appl…
- Geoffrey Smith A council worker who unlawfully accessed hundreds of personal records has been handed a suspended sentence.
Cause and consequence
Most sites cover one side or the other. The point of putting them together is that the link is real: the failure modes regulators fine organisations for are the same failure modes attackers rely on.
352 vulnerabilities · 2 UK cases
Ransomware, both ends
The vulnerabilities ransomware crews exploit, next to what ransomware has cost UK organisations in enforcement.
3 UK cases
Unpatched software
The most preventable cause on the register — and the exploited CVEs that are already past their fix deadline.
19 sectors
Who pays, and for what
Every UK sector the ICO has acted against, ranked by total penalties and dominant failure mode.
Sister publication
The breaches as they break
The Perimeter covers cyber-attacks and data breaches daily — the real-world incidents these exploited vulnerabilities cause.