vulnerability database
Vulnerability Database
Live CVE intelligence for researchers and engineers — ranked by real exploitation signals. The vulnerabilities most likely to be exploited (EPSS), those confirmed actively exploited (CISA KEV), and recent advisories across every major package ecosystem. Look up any CVE at /vulnerability/CVE-YYYY-NNNNN.
1,651
CISA KEV — actively exploited
28
Added to KEV (last 30 days)
up 7 month-over-month
771
High exploitation risk (EPSS ≥ 90%)
330
Ransomware-linked CVEs
Know the ID? Go straight to a record:
1,651 vulnerabilities are confirmed actively exploited in the CISA KEV catalog, with 28 added in the last 30 days (up 7 month-over-month). 771 CVEs carry an EPSS exploitation probability of at least 90%, led by CVE-2014-0160 at 100%. 330 KEV entries are linked to known ransomware campaigns.
Exploitability quadrant
EPSS × CVSS · CISA KEV CVEs — actively-exploited CVEs by likelihood × impact. Top-right = patch first.
100 CISA KEV (actively-exploited) CVEs plotted by exploitation likelihood (EPSS, x-axis) against impact (CVSS, y-axis). 34 sit in the top-right “patch first” zone — at least 50% EPSS probability and CVSS 7.0+ — making them the highest-priority vulnerabilities to remediate.
Severity of recent advisories
0 advisories
No recent advisories indexed yet.
Exploitability landscape
all scored CVEs · EPSS bands — how likely the CVE universe is to be exploited (log scale)
Bar length is log-scaled - counts span four orders of magnitude.
CISA KEV additions per month
newly confirmed-exploited
Recent vulnerabilities by ecosystem
stacked by severity
No recent per-ecosystem advisories indexed yet.
Find these CVEs in your own code
Impactr investigates and validates real attack paths in your web apps and APIs — not just whether a vulnerable package is present, but whether the vulnerable code is actually reachable, so you patch what matters and skip what doesn't.
Join the waitlistData last refreshed Jul 22, 2026 from CISA KEV, FIRST EPSS, the MITRE CVE Program, and the GitHub Advisory Database.