Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

Vulnerability Database

Live CVE intelligence for researchers and engineers — ranked by real exploitation signals. The vulnerabilities most likely to be exploited (EPSS), those confirmed actively exploited (CISA KEV), and recent advisories across every major package ecosystem. Look up any CVE at /vulnerability/CVE-YYYY-NNNNN.

1,653
CISA KEV — actively exploited
24
Added to KEV (last 30 days)
779
High exploitation risk (EPSS > 90%)
332
Ransomware-linked CVEs

Know the ID? Go straight to /vulnerability/CVE-2021-44228 or any CVE / GHSA.

1,653 vulnerabilities are confirmed actively exploited in the CISA KEV catalog, with 24 added in the last 30 days. 779 CVEs carry an EPSS exploitation probability above 90%, led by CVE-2024-3400 at 100%. 332 KEV entries are linked to known ransomware campaigns.

Exploitability quadrant

EPSS × CVSS · CISA KEV CVEs

Actively-exploited CVEs by likelihood × impact. Top-right = patch first.

100 CISA KEV (actively-exploited) CVEs plotted by exploitation likelihood (EPSS, x-axis) against impact (CVSS, y-axis). 44 sit in the top-right "patch first" zone — at least 50% EPSS probability and CVSS 7.0+ — making them the highest-priority vulnerabilities to remediate.

Severity of recent advisories

Critical2(4%)
High19(34%)
Medium23(41%)
Low12(21%)

Of 56 recent advisories across major ecosystems: 2 critical, 19 high, 23 medium, and 12 low severity.

CISA KEV additions per month

newly confirmed-exploited

CISA added 400 CVEs to its Known Exploited Vulnerabilities catalog over the last 18 months, including 23 in Jul 26. Each is confirmed exploited in the wild.

Exploitability landscape

all scored CVEs · EPSS bands

How likely the CVE universe is to be exploited (log scale).

Across all CVEs with an EPSS score: 779 are ≥ 90%, 3,522 are 50–90%, 12,941 are 10–50%, 335,048 are < 10% likely to be exploited within 30 days. The landscape is heavily skewed — the vast majority fall below 10%, so EPSS is effective at isolating the small set of genuinely high-risk CVEs.

Recent vulnerabilities by ecosystem

stacked by severity
CriticalHighMediumLow

Recent advisory volume per package ecosystem, each bar split into critical/high/medium/low. npm shows the most recent activity (8 advisories). Covers npm, PyPI, Go, Maven, RubyGems, crates.io, and NuGet.

Most actively exploited — right now

The vulnerabilities under the most active exploitation right now — all confirmed in the CISA Known Exploited Vulnerabilities catalog and ranked by EPSS exploitation probability — are led by CVE-2024-27199 (JetBrains TeamCity Relative Path Traversal, 100% EPSS), CVE-2026-10520 (Ivanti Sentry OS Command Injection, 100% EPSS), CVE-2026-48282 (Adobe ColdFusion Path Traversal, 99% EPSS). 2 of the top 8 are linked to known ransomware campaigns.

  1. 1
    CVE-2024-27199100% EPSSRansomware

    JetBrains TeamCity Relative Path Traversal VulnerabilityJetBrains TeamCity

    JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.

  2. 2
    CVE-2026-10520100% EPSS

    Ivanti Sentry OS Command Injection VulnerabilityIvanti Sentry

    Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

  3. 3
    CVE-2026-4828299% EPSS

    Adobe ColdFusion Path Traversal VulnerabilityAdobe ColdFusion

    Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

  4. 4
    CVE-2008-425099% EPSS

    Microsoft Windows Buffer Overflow VulnerabilityMicrosoft Windows

    Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

  5. 5
    CVE-2026-6303098% EPSS

    WordPress Core Interpretation Conflict VulnerabilityWordPress Core

    WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

  6. 6
    CVE-2026-3419797% EPSS

    Apache ActiveMQ Improper Input Validation VulnerabilityApache ActiveMQ

    Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

  7. 7
    CVE-2026-4194096% EPSSRansomware

    WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function VulnerabilityWebPros cPanel & WHM and WP2 (WordPress Squared)

    WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

  8. 8
    CVE-2026-2025396% EPSS

    Splunk Enterprise Missing Authentication for Critical Function VulnerabilitySplunk Enterprise

    Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.

Find these CVEs in your own code

O3 Security's Impact-Aware SCA correlates every CVE against your dependency graph and confirms whether the vulnerable code path is actually reachable — so you patch what matters, not the whole list.

Impact-Aware SCA