Vulnerability Database
Live CVE intelligence for researchers and engineers — ranked by real exploitation signals. The vulnerabilities most likely to be exploited (EPSS), those confirmed actively exploited (CISA KEV), and recent advisories across every major package ecosystem. Look up any CVE at /vulnerability/CVE-YYYY-NNNNN.
Know the ID? Go straight to /vulnerability/CVE-2021-44228 or any CVE / GHSA.
0 vulnerabilities are confirmed actively exploited in the CISA KEV catalog, with 0 added in the last 30 days. 797 CVEs carry an EPSS exploitation probability above 90%, led by CVE-2024-3400 at 100%. 0 KEV entries are linked to known ransomware campaigns.
Exploitability quadrant
EPSS × CVSS · CISA KEV CVEsActively-exploited CVEs by likelihood × impact. Top-right = patch first.
100 CISA KEV (actively-exploited) CVEs plotted by exploitation likelihood (EPSS, x-axis) against impact (CVSS, y-axis). 37 sit in the top-right "patch first" zone — at least 50% EPSS probability and CVSS 7.0+ — making them the highest-priority vulnerabilities to remediate.
Severity of recent advisories
Of 56 recent advisories across major ecosystems: 5 critical, 29 high, 20 medium, and 2 low severity.
CISA KEV additions per month
newly confirmed-exploitedTimeline feed briefly unavailable.
Exploitability landscape
all scored CVEs · EPSS bandsHow likely the CVE universe is to be exploited (log scale).
Across all CVEs with an EPSS score: 797 are ≥ 90%, 3,542 are 50–90%, 13,025 are 10–50%, 351,270 are < 10% likely to be exploited within 30 days. The landscape is heavily skewed — the vast majority fall below 10%, so EPSS is effective at isolating the small set of genuinely high-risk CVEs.
Recent vulnerabilities by ecosystem
stacked by severityRecent advisory volume per package ecosystem, each bar split into critical/high/medium/low. npm shows the most recent activity (8 advisories). Covers npm, PyPI, Go, Maven, RubyGems, crates.io, and NuGet.
Recently disclosed (last 7 days)
New HIGH and CRITICAL CVEs published in the past week, newest first — the vulnerabilities being researched and asked about right now, well before they reach the KEV catalog.
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipu…
A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L…
A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipul…
A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the ar…
A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Perfor…
A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation …
A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src…
A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The …
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL…
A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL…
A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a…
A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga…
A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/Uplo…
A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email res…
A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro…
A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInf…
A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/ja…
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_…
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing…
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a …
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such man…
A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This m…
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. …
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attack…
A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email ca…
A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handle…
h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers ca…
A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of…
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delet…
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the ar…
Trending by exploitation probability (EPSS)
The CVEs FIRST.org's EPSS model predicts are most likely to be exploited next — and that aren't yet in the CISA KEV catalog. The forward-looking signal, ahead of confirmed exploitation.
Confirmed actively-exploited (CISA KEV) vulnerabilities ranked by EPSS — the probability of exploitation within 30 days. Each names the affected vendor or product and what the flaw is.
Recently added to CISA KEV (confirmed exploited)
These are actively exploited in the wild — CISA requires US federal agencies to remediate them by a deadline. Treat them as top priority.
KEV feed briefly unavailable.
Recent vulnerabilities by ecosystem
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Material for MkDocs: DOM XSS in search suggestions via query parameter
unstructured: Server-Side Request Forgery in the URL-based partitioning
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
MapFish Print has XXE that allows reading arbitrary files of certain types
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
Mail: Email address spoofing via malformed RFC 2047 encoded-words
Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute
Duplicate Advisory: Nokogiri CSS selector tokenizer has regular expression backtracking
Duplicate Advisory: Nokogiri XSLT transform has a memory leak
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
guard-livereload has a directory traversal vulnerability
Savon::Model evaluates WSDL operation names as Ruby source
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
ImageMagick: Memory Leak when providing invalid options to the cli
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
How fresh is this vulnerability data?
It updates throughout the day. When CISA flags a vulnerability as actively exploited, or a new advisory lands for an npm or PyPI package, it shows up here the same day — usually within the hour. Exploitation-probability (EPSS) scores refresh daily.
What is the CISA KEV (Known Exploited Vulnerabilities) catalog?
It's the US government's list of vulnerabilities that attackers are actively exploiting in the real world — not theoretical risks, but ones with confirmed attacks behind them. Federal agencies are required to patch anything on it by a deadline. If a CVE is on this list, treat it as urgent.
What does an EPSS score actually tell me?
EPSS is a probability: the chance a vulnerability will actually be exploited in the next 30 days, from 0 to 100%. It cuts through the noise — most CVEs are never exploited, and EPSS helps you spot the small handful that likely will be, so you can fix those first.
CVSS, EPSS, KEV — what's the difference, and which matters?
They answer different questions. CVSS tells you how damaging a vulnerability would be if exploited (severity, 0–10). EPSS tells you how likely it is to be exploited soon. KEV tells you it already is. A scary CVSS score on its own doesn't mean you're in danger — pair it with a high EPSS or a KEV listing and you know what to patch today.
Which package ecosystems are covered?
All the major ones — npm, PyPI, Go, Maven, RubyGems, crates.io (Rust) and NuGet — plus everything else tracked by OSV, and vendor software CVEs from the National Vulnerability Database. If a CVE or GitHub advisory exists, you can pull it up here.
How do I look up a specific CVE?
Just add the ID to the address: o3.security/vulnerability/CVE-2021-44228, for instance. GitHub (GHSA) advisory IDs work the same way. You'll get the severity, which packages and products are affected, whether it's being exploited, and how to fix it — all on one page.
Where does the data come from?
From the sources security teams already trust: OSV and the GitHub Advisory Database for open-source packages, the National Vulnerability Database for vendor software, CISA's KEV catalog for active exploitation, and FIRST.org for EPSS. O3 brings them together and adds reachability analysis, so you can see which of these actually reach your code.
Find these CVEs in your own code
O3 Security's Impact-Aware SCA correlates every CVE against your dependency graph and confirms whether the vulnerable code path is actually reachable — so you patch what matters, not the whole list.
Impact-Aware SCA