vulnerability database
Vulnerability Database
Live CVE intelligence for researchers and engineers — ranked by real exploitation signals. The vulnerabilities most likely to be exploited (EPSS), those confirmed actively exploited (CISA KEV), and recent advisories across every major package ecosystem. Look up any CVE at /vulnerability/CVE-YYYY-NNNNN.
1,694
CISA KEV — actively exploited
34
Added to KEV (last 30 days)
up 5 month-over-month
796
High exploitation risk (EPSS ≥ 90%)
352
Ransomware-linked CVEs
Know the ID? Go straight to a record:
1,694 vulnerabilities are confirmed actively exploited in the CISA KEV catalog, with 34 added in the last 30 days (up 5 month-over-month). 796 CVEs carry an EPSS exploitation probability of at least 90%, led by CVE-2014-0160 at 100%. 352 KEV entries are linked to known ransomware campaigns.
Exploitability quadrant
EPSS × CVSS · CISA KEV CVEs — actively-exploited CVEs by likelihood × impact. Top-right = patch first.
100 CISA KEV (actively-exploited) CVEs plotted by exploitation likelihood (EPSS, x-axis) against impact (CVSS, y-axis). 36 sit in the top-right “patch first” zone — at least 50% EPSS probability and CVSS 7.0+ — making them the highest-priority vulnerabilities to remediate.
Severity of recent advisories
80 advisories
- Critical
- 7 (9%)
- High
- 37 (46%)
- Medium
- 34 (43%)
- Low
- 2 (3%)
Exploitability landscape
all scored CVEs · EPSS bands — how likely the CVE universe is to be exploited (log scale)
Bar length is log-scaled - counts span four orders of magnitude.
CISA KEV additions per month
newly confirmed-exploited
Recent vulnerabilities by ecosystem
stacked by severity
Recent advisories
Newest ecosystem advisories, most recent first.
- CVE-2026-73667
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
GoHighSep 2, 2026 - CVE-2026-73840
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
GoMediumSep 2, 2026 - CVE-2026-73841
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
GoHighSep 2, 2026 - CVE-2026-73843
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
GoCriticalSep 2, 2026 - CVE-2026-67445
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection
GoHighSep 2, 2026 - CVE-2026-72921
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths
GoHighSep 2, 2026 - CVE-2026-67446
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
GoHighSep 2, 2026 - CVE-2026-84366
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
PyPIHighSep 2, 2026 - CVE-2026-68921
DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
npmMediumSep 2, 2026 - CVE-2026-62676
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
PyPIHighSep 2, 2026 - CVE-2026-65842
Plate: SSRF with response disclosure in DOCX image embedding
npmHighSep 2, 2026 - CVE-2026-63490
Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
MavenHighSep 2, 2026 - CVE-2026-63435
Mail: Email address spoofing via malformed RFC 2047 encoded-words
RubyGemsMediumSep 2, 2026 - CVE-2026-62677
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
PyPIHighSep 2, 2026 - CVE-2026-62674
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
PyPICriticalSep 2, 2026 - CVE-2026-62675
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
PyPIHighSep 2, 2026 - CVE-2026-61704
link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
npmHighSep 2, 2026 - CVE-2026-75931
fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
npmHighSep 2, 2026 - CVE-2026-75975
fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization
npmHighSep 2, 2026 - CVE-2026-75899
fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
npmHighSep 2, 2026 - CVE-2026-76172
fast-uri vulnerable to host confusion via percent-encoded scheme normalization
npmHighSep 2, 2026 - CVE-2026-62388
NLTK: Default ENFORCE=False Disables All pathsec Security Controls
PyPIHighSep 2, 2026 - CVE-2026-63311
NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure
PyPIMediumSep 2, 2026 - CVE-2026-83610
xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
npmMediumSep 2, 2026 - CVE-2026-76098
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown
PyPIHighSep 2, 2026 - CVE-2026-16732
fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
npmMediumSep 2, 2026 - CVE-2026-18504
fastify vulnerable to schema validation bypass via root primitive coercion mismatch
npmMediumSep 2, 2026 - CVE-2026-71553
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
npmHighSep 2, 2026 - CVE-2026-63667
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
npmMediumSep 2, 2026 - CVE-2026-62680
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
npmHighSep 2, 2026
Most exploited — right now
CISA KEV CVEs ranked by EPSS exploitation probability.
- 1CVE-2021-26086100% EPSS
Atlassian Jira Server and Data Center Path Traversal Vulnerability — Atlassian
Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
- 2CVE-2024-23897100% EPSSRansomware
Jenkins Command Line Interface (CLI) Path Traversal Vulnerability — Jenkins
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.
- 3CVE-2024-3400100% EPSSRansomware
Palo Alto Networks PAN-OS Command Injection Vulnerability — Palo Alto Networks
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
- 4CVE-2024-21893100% EPSSRansomware
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability — Ivanti
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.
- 5CVE-2023-35082100% EPSSRansomware
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability — Ivanti
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.
- 6CVE-2024-21887100% EPSSRansomware
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability — Ivanti
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.
- 7CVE-2023-1671100% EPSS
Sophos Web Appliance Command Injection Vulnerability — Sophos
Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.
- 8CVE-2023-22518100% EPSSRansomware
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability — Atlassian
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.
- 9CVE-2023-4966100% EPSSRansomware
Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability — Citrix
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
- 10CVE-2023-44487100% EPSS
HTTP/2 Rapid Reset Attack Vulnerability — IETF
HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS).
- 11CVE-2023-32315100% EPSS
Ignite Realtime Openfire Path Traversal Vulnerability — Ignite Realtime
Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users.
- 12CVE-2023-35078100% EPSSRansomware
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability — Ivanti
Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.
- 13CVE-2023-1389100% EPSS
TP-Link Archer AX-21 Command Injection Vulnerability — TP-Link
TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.
- 14CVE-2023-27350100% EPSSRansomware
PaperCut MF/NG Improper Access Control Vulnerability — PaperCut
PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.
- 15CVE-2023-0669100% EPSSRansomware
Fortra GoAnywhere MFT Remote Code Execution Vulnerability — Fortra
Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet due to deserializing an attacker-controlled object.
- 16CVE-2022-26134100% EPSSRansomware
Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability — Atlassian
Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.
- 17CVE-2014-0160100% EPSS
OpenSSL Information Disclosure Vulnerability — OpenSSL
The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
- 18CVE-2022-29464100% EPSSRansomware
WSO2 Multiple Products Unrestrictive Upload of File Vulnerability — WSO2
Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
- 19CVE-2017-9841100% EPSS
PHPUnit Command Injection Vulnerability — PHPUnit
PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.
- 20CVE-2015-1635100% EPSS
Microsoft HTTP.sys Remote Code Execution Vulnerability — Microsoft
Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
- 21CVE-2014-6271100% EPSS
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability — GNU
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.
- 22CVE-2021-44228100% EPSSRansomware
Apache Log4j2 Remote Code Execution Vulnerability — Apache
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
- 23CVE-2021-40438100% EPSSRansomware
Apache HTTP Server-Side Request Forgery (SSRF) — Apache
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
- 24CVE-2017-5638100% EPSSRansomware
Apache Struts Remote Code Execution Vulnerability — Apache
Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.
- 25CVE-2021-26084100% EPSSRansomware
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability — Atlassian
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
- 26CVE-2021-1498100% EPSS
Cisco HyperFlex HX Data Platform Command Injection Vulnerability — Cisco
Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
- 27CVE-2019-19781100% EPSSRansomware
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability — Citrix
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.
- 28CVE-2020-5902100% EPSSRansomware
F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability — F5
F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
- 29CVE-2021-35464100% EPSSRansomware
ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability — ForgeRock
ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend).
- 30CVE-2018-13379100% EPSSRansomware
Fortinet FortiOS SSL VPN Path Traversal Vulnerability — Fortinet
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
- 31CVE-2019-0708100% EPSSRansomware
Microsoft Remote Desktop Services Remote Code Execution Vulnerability — Microsoft
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.
- 32CVE-2021-34473100% EPSSRansomware
Microsoft Exchange Server Remote Code Execution Vulnerability — Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
- 33CVE-2019-11510100% EPSSRansomware
Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability — Ivanti
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
- 34CVE-2021-22005100% EPSSRansomware
VMware vCenter Server File Upload Vulnerability — VMware
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
- 35CVE-2021-21985100% EPSSRansomware
VMware vCenter Server Improper Input Validation Vulnerability — VMware
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
- 36CVE-2017-7921100% EPSS
Hikvision Multiple Products Improper Authentication Vulnerability — Hikvision
Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.
- 37CVE-2025-53770100% EPSSRansomware
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability — Microsoft
Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.
- 38CVE-2013-2251100% EPSS
Apache Struts Improper Input Validation Vulnerability — Apache
Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
- 39CVE-2012-1823100% EPSS
PHP-CGI Query String Parameter Vulnerability — PHP
sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
- 40CVE-2024-3273100% EPSS
D-Link Multiple NAS Devices Command Injection Vulnerability — D-Link
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.
- 41CVE-2022-22954100% EPSSRansomware
VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability — VMware
VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
- 42CVE-2020-14882100% EPSS
Oracle WebLogic Server Remote Code Execution Vulnerability — Oracle
Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.
- 43CVE-2025-3248100% EPSSRansomware
Langflow Missing Authentication Vulnerability — Langflow
Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.
- 44CVE-2019-16920100% EPSS
D-Link Multiple Routers Command Injection Vulnerability — D-Link
Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.
- 45CVE-2021-26855100% EPSSRansomware
Microsoft Exchange Server Remote Code Execution Vulnerability — Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- 46CVE-2025-49704100% EPSSRansomware
Microsoft SharePoint Code Injection Vulnerability — Microsoft
Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.
- 47CVE-2022-44877100% EPSS
CWP Control Web Panel OS Command Injection Vulnerability — CWP
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.
- 48CVE-2024-34102100% EPSS
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability — Adobe
Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
- 49CVE-2017-10271100% EPSSRansomware
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability — Oracle
Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
- 50CVE-2020-8515100% EPSS
Multiple DrayTek Vigor Routers Web Management Page Vulnerability — DrayTek
DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.
Recently added to CISA KEV
1,694 total confirmed actively-exploited CVEs
- CVE-2026-59822BerriAI LiteLLM Improper Authentication Vulnerabilityadded Sep 2, 2026 · 1% EPSS
- CVE-2026-48710Kludex Starlette HTTP Request/Response Smuggling Vulnerabilityadded Sep 2, 2026 · 2% EPSS
- CVE-2026-49869Kestra OSS OS Command Injection Vulnerabilityadded Sep 2, 2026 · 1% EPSS
- CVE-2026-82329JFrog Artifactory Improper Authentication Vulnerabilityadded Sep 2, 2026 · 1% EPSS
- CVE-2026-9586Sangoma Switchvox SQL Injection Vulnerabilityadded Sep 2, 2026 · 1% EPSS
- CVE-2026-83548SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerabilityadded Sep 2, 2026 · 0% EPSS
- CVE-2026-83549SonicWall SMA1000 Appliances OS Command Injection Vulnerabilityadded Sep 2, 2026 · 1% EPSS
- CVE-2026-82078PaperCut NG/MF Unsafe Reflection Vulnerabilityadded Aug 31, 2026 · 1% EPSS
- CVE-2026-81578PaperCut NG/MF Missing Authentication for Critical Function Vulnerabilityadded Aug 31, 2026 · 1% EPSS
- CVE-2023-49105ownCloud Improper Authentication Vulnerabilityadded Aug 27, 2026 · 43% EPSS
- CVE-2026-53362Linux Kernel Unspecified Vulnerabilityadded Aug 27, 2026 · 1% EPSS
- CVE-2026-66384JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerabilityadded Aug 27, 2026 · 1% EPSS
- CVE-2021-23758Ajax.NET Professional Deserialization of Untrusted Data Vulnerabilityadded Aug 26, 2026 · 84% EPSS
- CVE-2015-3246Red Hat Libuser Race Condition Vulnerabilityadded Aug 26, 2026 · 9% EPSS
- CVE-2015-5287Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerabilityadded Aug 26, 2026 · 5% EPSS
- CVE-2022-0995Linux Kernel Out-of-Bounds Write Vulnerabilityadded Aug 26, 2026 · 10% EPSS
- CVE-2026-8452Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerabilityadded Aug 26, 2026 · 2% EPSS
- CVE-2019-1068Microsoft SQL Server Remote Code Execution Vulnerabilityadded Aug 26, 2026 · 53% EPSS
- CVE-2026-60004Gitea Code Injection Vulnerabilityadded Aug 25, 2026 · 87% EPSS
- CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerabilityadded Aug 24, 2026 · 42% EPSS
- CVE-2026-73570Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerabilityadded Aug 21, 2026 · 21% EPSS
- CVE-2026-72530TrueConf Server Code Injection Vulnerabilityadded Aug 20, 2026 · 2% EPSS
- CVE-2026-72529TrueConf Server Missing Authentication for Critical Function Vulnerabilityadded Aug 20, 2026 · 2% EPSS
- CVE-2026-64849MLflow Server-Side Request Forgery Vulnerabilityadded Aug 19, 2026 · 16% EPSS
- CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerabilityadded Aug 18, 2026 · 73% EPSS
- CVE-2026-59310Broadcom VMware vCenter Path Traversal Vulnerabilityadded Aug 18, 2026 · 46% EPSS
- CVE-2026-55040Microsoft SharePoint Weak Authentication Vulnerabilityadded Aug 18, 2026 · 40% EPSS
- CVE-2026-65400Apple macOS Improper Authentication Vulnerabilityadded Aug 18, 2026 · 10% EPSS
- CVE-2025-62593Ray-Project Ray Code Injection Vulnerabilityadded Aug 17, 2026 · 17% EPSS
- CVE-2026-20349Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerabilityadded Aug 11, 2026 · 2% EPSS
Recent vulnerabilities by ecosystem
npm, PyPI, Go, Maven, RubyGems, crates.io, and NuGet — stacked by severity.
Frequently asked questions
What is EPSS?
The Exploit Prediction Scoring System (EPSS) is a FIRST.org model that estimates the probability a vulnerability will be exploited in the wild in the next 30 days, scored 0-100% from real-world signals (references, chatter, existing exploit code). It answers 'how likely,' which is a different question from CVSS's 'how bad if exploited.'
What is the CISA KEV catalog?
The Known Exploited Vulnerabilities (KEV) catalog is CISA's list of vulnerabilities with confirmed evidence of active exploitation. Unlike EPSS (a probability), KEV listing means exploitation has already happened - it is the highest-confidence signal available and the basis for U.S. federal patching deadlines.
Why do EPSS and CVSS disagree so often?
CVSS scores potential severity if a flaw is exploited; EPSS scores the likelihood it will be. A CVSS 9.8 vulnerability with no public exploit code can carry a low EPSS score, while a CVSS 7.0 flaw with a trivial, widely-circulated exploit can score near 100% on EPSS. Prioritize by both: the quadrant chart's top-right corner (high likelihood and high impact) is where to patch first.
What does 'ransomware-linked' mean here?
It flags CISA KEV entries where CISA has documented the vulnerability being used in ransomware campaigns. It is a conservative, evidence-based tag, not a prediction - absence of the tag does not mean a CVE is safe from ransomware use, only that CISA has not documented it yet.
How current is this data?
KEV, EPSS, and ecosystem advisory data refresh daily from CISA, FIRST.org, and the GitHub Advisory Database. Individual CVE pages additionally cross-check the MITRE CVE record, NVD, and public GitHub repositories at request time.
Find these CVEs in your own code
Impactr investigates and validates real attack paths in your web apps and APIs — not just whether a vulnerable package is present, but whether the vulnerable code is actually reachable, so you patch what matters and skip what doesn't.
Join the waitlistData last refreshed Sep 3, 2026 from CISA KEV, FIRST EPSS, the MITRE CVE Program, and the GitHub Advisory Database.