Vulnerability Database
Live CVE intelligence for researchers and engineers — ranked by real exploitation signals. The vulnerabilities most likely to be exploited (EPSS), those confirmed actively exploited (CISA KEV), and recent advisories across every major package ecosystem. Look up any CVE at /vulnerability/CVE-YYYY-NNNNN.
Know the ID? Go straight to /vulnerability/CVE-2021-44228 or any CVE / GHSA.
0 vulnerabilities are confirmed actively exploited in the CISA KEV catalog, with 0 added in the last 30 days. 798 CVEs carry an EPSS exploitation probability above 90%. 0 KEV entries are linked to known ransomware campaigns.
Exploitability quadrant
EPSS × CVSS · CISA KEV CVEsActively-exploited CVEs by likelihood × impact. Top-right = patch first.
100 CISA KEV (actively-exploited) CVEs plotted by exploitation likelihood (EPSS, x-axis) against impact (CVSS, y-axis). 0 sit in the top-right "patch first" zone — at least 50% EPSS probability and CVSS 7.0+ — making them the highest-priority vulnerabilities to remediate.
Severity of recent advisories
Of 56 recent advisories across major ecosystems: 5 critical, 29 high, 20 medium, and 2 low severity.
CISA KEV additions per month
newly confirmed-exploitedTimeline feed briefly unavailable.
Exploitability landscape
all scored CVEs · EPSS bandsHow likely the CVE universe is to be exploited (log scale).
Across all CVEs with an EPSS score: 798 are ≥ 90%, 3,543 are 50–90%, 13,024 are 10–50%, 351,405 are < 10% likely to be exploited within 30 days. The landscape is heavily skewed — the vast majority fall below 10%, so EPSS is effective at isolating the small set of genuinely high-risk CVEs.
Recent vulnerabilities by ecosystem
stacked by severityRecent advisory volume per package ecosystem, each bar split into critical/high/medium/low. npm shows the most recent activity (8 advisories). Covers npm, PyPI, Go, Maven, RubyGems, crates.io, and NuGet.
Recently disclosed (last 7 days)
New HIGH and CRITICAL CVEs published in the past week, newest first — the vulnerabilities being researched and asked about right now, well before they reach the KEV catalog.
A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certifica…
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past …
A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control…
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-…
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation ca…
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted n…
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers c…
knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply t…
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Custo…
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An una…
Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: fr…
A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler…
A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipul…
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL…
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL…
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of t…
A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument …
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to …
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Execu…
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Managemen…
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface…
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulatio…
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live se…
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-c…
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by em…
AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attacke…
Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthentica…
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arb…
SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping…
FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perfor…
Trending by exploitation probability (EPSS)
The CVEs FIRST.org's EPSS model predicts are most likely to be exploited next — and that aren't yet in the CISA KEV catalog. The forward-looking signal, ahead of confirmed exploitation.
EPSS trending data briefly unavailable.
Confirmed actively-exploited (CISA KEV) vulnerabilities ranked by EPSS — the probability of exploitation within 30 days. Each names the affected vendor or product and what the flaw is.
Recently added to CISA KEV (confirmed exploited)
These are actively exploited in the wild — CISA requires US federal agencies to remediate them by a deadline. Treat them as top priority.
KEV feed briefly unavailable.
Recent vulnerabilities by ecosystem
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Material for MkDocs: DOM XSS in search suggestions via query parameter
unstructured: Server-Side Request Forgery in the URL-based partitioning
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
MapFish Print has XXE that allows reading arbitrary files of certain types
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
Mail: Email address spoofing via malformed RFC 2047 encoded-words
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking
Duplicate Advisory: Nokogiri XSLT transform has a memory leak
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
guard-livereload has a directory traversal vulnerability
Savon::Model evaluates WSDL operation names as Ruby source
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
ImageMagick: Memory Leak when providing invalid options to the cli
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
How fresh is this vulnerability data?
It updates throughout the day. When CISA flags a vulnerability as actively exploited, or a new advisory lands for an npm or PyPI package, it shows up here the same day — usually within the hour. Exploitation-probability (EPSS) scores refresh daily.
What is the CISA KEV (Known Exploited Vulnerabilities) catalog?
It's the US government's list of vulnerabilities that attackers are actively exploiting in the real world — not theoretical risks, but ones with confirmed attacks behind them. Federal agencies are required to patch anything on it by a deadline. If a CVE is on this list, treat it as urgent.
What does an EPSS score actually tell me?
EPSS is a probability: the chance a vulnerability will actually be exploited in the next 30 days, from 0 to 100%. It cuts through the noise — most CVEs are never exploited, and EPSS helps you spot the small handful that likely will be, so you can fix those first.
CVSS, EPSS, KEV — what's the difference, and which matters?
They answer different questions. CVSS tells you how damaging a vulnerability would be if exploited (severity, 0–10). EPSS tells you how likely it is to be exploited soon. KEV tells you it already is. A scary CVSS score on its own doesn't mean you're in danger — pair it with a high EPSS or a KEV listing and you know what to patch today.
Which package ecosystems are covered?
All the major ones — npm, PyPI, Go, Maven, RubyGems, crates.io (Rust) and NuGet — plus everything else tracked by OSV, and vendor software CVEs from the National Vulnerability Database. If a CVE or GitHub advisory exists, you can pull it up here.
How do I look up a specific CVE?
Just add the ID to the address: o3.security/vulnerability/CVE-2021-44228, for instance. GitHub (GHSA) advisory IDs work the same way. You'll get the severity, which packages and products are affected, whether it's being exploited, and how to fix it — all on one page.
Where does the data come from?
From the sources security teams already trust: OSV and the GitHub Advisory Database for open-source packages, the National Vulnerability Database for vendor software, CISA's KEV catalog for active exploitation, and FIRST.org for EPSS. O3 brings them together and adds reachability analysis, so you can see which of these actually reach your code.
Find these CVEs in your own code
O3 Security's Impact-Aware SCA correlates every CVE against your dependency graph and confirms whether the vulnerable code path is actually reachable — so you patch what matters, not the whole list.
Impact-Aware SCA