Your RSA-2048 keys break in 2030. Find every one of them before attackers do.

Vulnerability Database

Live CVE intelligence for researchers and engineers — ranked by real exploitation signals. The vulnerabilities most likely to be exploited (EPSS), those confirmed actively exploited (CISA KEV), and recent advisories across every major package ecosystem. Look up any CVE at /vulnerability/CVE-YYYY-NNNNN.

CISA KEV — actively exploited
Added to KEV (last 30 days)
798
High exploitation risk (EPSS > 90%)
Ransomware-linked CVEs

Know the ID? Go straight to /vulnerability/CVE-2021-44228 or any CVE / GHSA.

0 vulnerabilities are confirmed actively exploited in the CISA KEV catalog, with 0 added in the last 30 days. 798 CVEs carry an EPSS exploitation probability above 90%. 0 KEV entries are linked to known ransomware campaigns.

Exploitability quadrant

EPSS × CVSS · CISA KEV CVEs

Actively-exploited CVEs by likelihood × impact. Top-right = patch first.

100 CISA KEV (actively-exploited) CVEs plotted by exploitation likelihood (EPSS, x-axis) against impact (CVSS, y-axis). 0 sit in the top-right "patch first" zone — at least 50% EPSS probability and CVSS 7.0+ — making them the highest-priority vulnerabilities to remediate.

Severity of recent advisories

Critical5(9%)
High29(52%)
Medium20(36%)
Low2(4%)

Of 56 recent advisories across major ecosystems: 5 critical, 29 high, 20 medium, and 2 low severity.

CISA KEV additions per month

newly confirmed-exploited

Timeline feed briefly unavailable.

Exploitability landscape

all scored CVEs · EPSS bands

How likely the CVE universe is to be exploited (log scale).

Across all CVEs with an EPSS score: 798 are ≥ 90%, 3,543 are 50–90%, 13,024 are 10–50%, 351,405 are < 10% likely to be exploited within 30 days. The landscape is heavily skewed — the vast majority fall below 10%, so EPSS is effective at isolating the small set of genuinely high-risk CVEs.

Recent vulnerabilities by ecosystem

stacked by severity
CriticalHighMediumLow

Recent advisory volume per package ecosystem, each bar split into critical/high/medium/low. npm shows the most recent activity (8 advisories). Covers npm, PyPI, Go, Maven, RubyGems, crates.io, and NuGet.

Find these CVEs in your own code

O3 Security's Impact-Aware SCA correlates every CVE against your dependency graph and confirms whether the vulnerable code path is actually reachable — so you patch what matters, not the whole list.

Impact-Aware SCA