Vulnerability Database
Live CVE intelligence for researchers and engineers — ranked by real exploitation signals. The vulnerabilities most likely to be exploited (EPSS), those confirmed actively exploited (CISA KEV), and recent advisories across every major package ecosystem. Look up any CVE at /vulnerability/CVE-YYYY-NNNNN.
Know the ID? Go straight to /vulnerability/CVE-2021-44228 or any CVE / GHSA.
1,653 vulnerabilities are confirmed actively exploited in the CISA KEV catalog, with 24 added in the last 30 days. 779 CVEs carry an EPSS exploitation probability above 90%, led by CVE-2024-3400 at 100%. 332 KEV entries are linked to known ransomware campaigns.
Exploitability quadrant
EPSS × CVSS · CISA KEV CVEsActively-exploited CVEs by likelihood × impact. Top-right = patch first.
100 CISA KEV (actively-exploited) CVEs plotted by exploitation likelihood (EPSS, x-axis) against impact (CVSS, y-axis). 44 sit in the top-right "patch first" zone — at least 50% EPSS probability and CVSS 7.0+ — making them the highest-priority vulnerabilities to remediate.
Severity of recent advisories
Of 56 recent advisories across major ecosystems: 2 critical, 19 high, 23 medium, and 12 low severity.
CISA KEV additions per month
newly confirmed-exploitedCISA added 400 CVEs to its Known Exploited Vulnerabilities catalog over the last 18 months, including 23 in Jul 26. Each is confirmed exploited in the wild.
Exploitability landscape
all scored CVEs · EPSS bandsHow likely the CVE universe is to be exploited (log scale).
Across all CVEs with an EPSS score: 779 are ≥ 90%, 3,522 are 50–90%, 12,941 are 10–50%, 335,048 are < 10% likely to be exploited within 30 days. The landscape is heavily skewed — the vast majority fall below 10%, so EPSS is effective at isolating the small set of genuinely high-risk CVEs.
Recent vulnerabilities by ecosystem
stacked by severityRecent advisory volume per package ecosystem, each bar split into critical/high/medium/low. npm shows the most recent activity (8 advisories). Covers npm, PyPI, Go, Maven, RubyGems, crates.io, and NuGet.
Most actively exploited — right now
The vulnerabilities under the most active exploitation right now — all confirmed in the CISA Known Exploited Vulnerabilities catalog and ranked by EPSS exploitation probability — are led by CVE-2024-27199 (JetBrains TeamCity Relative Path Traversal, 100% EPSS), CVE-2026-10520 (Ivanti Sentry OS Command Injection, 100% EPSS), CVE-2026-48282 (Adobe ColdFusion Path Traversal, 99% EPSS). 2 of the top 8 are linked to known ransomware campaigns.
- 1CVE-2024-27199100% EPSSRansomware
JetBrains TeamCity Relative Path Traversal Vulnerability — JetBrains TeamCity
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
- 2CVE-2026-10520100% EPSS
Ivanti Sentry OS Command Injection Vulnerability — Ivanti Sentry
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
- 3CVE-2026-4828299% EPSS
Adobe ColdFusion Path Traversal Vulnerability — Adobe ColdFusion
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
- 4CVE-2008-425099% EPSS
Microsoft Windows Buffer Overflow Vulnerability — Microsoft Windows
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
- 5CVE-2026-6303098% EPSS
WordPress Core Interpretation Conflict Vulnerability — WordPress Core
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
- 6CVE-2026-3419797% EPSS
Apache ActiveMQ Improper Input Validation Vulnerability — Apache ActiveMQ
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
- 7CVE-2026-4194096% EPSSRansomware
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability — WebPros cPanel & WHM and WP2 (WordPress Squared)
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
- 8CVE-2026-2025396% EPSS
Splunk Enterprise Missing Authentication for Critical Function Vulnerability — Splunk Enterprise
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
Recently disclosed (last 7 days)
New HIGH and CRITICAL CVEs published in the past week, newest first — the vulnerabilities being researched and asked about right now, well before they reach the KEV catalog.
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is d…
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line a…
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap…
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supply…
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplyin…
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy…
libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a…
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY…
gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execu…
Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage b…
Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write atta…
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary…
CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers …
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. Wh…
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious …
Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.…
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easi…
Vulnerability in the Oracle Common Application Components product of Oracle E-Business Suite (component: Oracle Common Modules). Supported versions that are affected are 12.2.3…
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and …
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and …
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and …
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and …
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and …
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and …
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and …
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and …
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and …
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and …
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0…
Trending by exploitation probability (EPSS)
The CVEs FIRST.org's EPSS model predicts are most likely to be exploited next — and that aren't yet in the CISA KEV catalog. The forward-looking signal, ahead of confirmed exploitation.
Confirmed actively-exploited (CISA KEV) vulnerabilities ranked by EPSS — the probability of exploitation within 30 days. Each names the affected vendor or product and what the flaw is.
Ranked by exploitation likelihood
- 1CVE-2024-27199100% EPSSRansomware
JetBrains TeamCity Relative Path Traversal Vulnerability — JetBrains TeamCity
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
- 2CVE-2026-10520100% EPSS
Ivanti Sentry OS Command Injection Vulnerability — Ivanti Sentry
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
- 3CVE-2026-4828299% EPSS
Adobe ColdFusion Path Traversal Vulnerability — Adobe ColdFusion
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
- 4CVE-2008-425099% EPSS
Microsoft Windows Buffer Overflow Vulnerability — Microsoft Windows
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
- 5CVE-2026-6303098% EPSS
WordPress Core Interpretation Conflict Vulnerability — WordPress Core
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
- 6CVE-2026-3419797% EPSS
Apache ActiveMQ Improper Input Validation Vulnerability — Apache ActiveMQ
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
- 7CVE-2026-4194096% EPSSRansomware
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability — WebPros cPanel & WHM and WP2 (WordPress Squared)
WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
- 8CVE-2026-2025396% EPSS
Splunk Enterprise Missing Authentication for Critical Function Vulnerability — Splunk Enterprise
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
- 9CVE-2026-3998795% EPSS
Marimo Remote Code Execution Vulnerability — Marimo Marimo
Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
- 10CVE-2026-3143195% EPSS
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability — Linux Kernel
Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
- 11CVE-2026-2164394% EPSS
Fortinet FortiClient EMS SQL Injection Vulnerability — Fortinet FortiClient EMS
Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
- 12CVE-2026-3527394% EPSSRansomware
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability — Oracle PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
- 13CVE-2026-025794% EPSSRansomware
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability — Palo Alto Networks PAN-OS
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
- 14CVE-2024-739992% EPSS
Samsung MagicINFO 9 Server Path Traversal Vulnerability — Samsung MagicINFO 9 Server
Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.
- 15CVE-2010-024992% EPSS
Microsoft Internet Explorer Use-After-Free Vulnerability — Microsoft Internet Explorer
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
- 16CVE-2026-2018290% EPSS
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability — Cisco Catalyst SD-WAN
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
- 17CVE-2026-3980890% EPSS
Fortinet FortiSandbox OS Command Injection Vulnerability — Fortinet FortiSandbox
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
- 18CVE-2025-2963590% EPSS
D-Link DIR-823X Command Injection Vulnerability — D-Link DIR-823X
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
- 19CVE-2026-3561689% EPSS
Fortinet FortiClient EMS Improper Access Control Vulnerability — Fortinet FortiClient EMS
Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
- 20CVE-2026-908288% EPSS
Drupal Core SQL Injection Vulnerability — Drupal Core
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
- 21CVE-2026-4890888% EPSS
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability — JoomShaper SP Page Builder
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
- 22CVE-2024-170888% EPSSRansomware
ConnectWise ScreenConnect Path Traversal Vulnerability — ConnectWise ScreenConnect
ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
- 23CVE-2026-4220887% EPSS
BerriAI LiteLLM SQL Injection Vulnerability — BerriAI LiteLLM
BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.
- 24CVE-2026-3491087% EPSS
Ubiquiti UniFi OS Improper Input Validation Vulnerability — Ubiquiti UniFi OS
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Recently added to CISA KEV (confirmed exploited)
These are actively exploited in the wild — CISA requires US federal agencies to remediate them by a deadline. Treat them as top priority.
Vendors under active exploitation
recent KEV entriesMicrosoft leads recent CISA KEV additions with 10 actively-exploited CVEs, followed by Cisco (4) and Langflow (3).
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability — Microsoft SharePoint
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Check Point SmartConsole Improper Authentication Vulnerability — Check Point SmartConsole
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
DD-WRT Stack-Based Buffer Overflow Vulnerability — DD-WRT DD-WRT
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability — Langflow Langflow
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
WordPress Core Interpretation Conflict Vulnerability — WordPress Core
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
WordPress Core SQL Injection Vulnerability — WordPress Core
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Fortinet FortiSandbox OS Command Injection Vulnerability — Fortinet FortiSandbox
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Fortinet FortiSandbox OS Command Injection Vulnerability — Fortinet FortiSandbox
Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability — Microsoft SharePoint
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability — KNX Association KNX Protocol Connection Authorization Option 1
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.
Oracle E-Business Suite Improper Privilege Management Vulnerability — Oracle E-Business Suite
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
SonicWall SMA1000 Appliances Code Injection Vulnerability — SonicWall SMA1000 Appliances
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability — SonicWall SMA1000 Appliances
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability — Microsoft SharePoint Server
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability — Microsoft Active Directory Federation Services
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
Cisco IOS Cross-Site Request Forgery Vulnerability — Cisco IOS
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability — iCagenda iCagenda
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability — Balbooa Forms
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
Adobe ColdFusion Path Traversal Vulnerability — Adobe ColdFusion
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Joomlack Page Builder Improper Access Control Vulnerability — Joomlack Page Builder
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Langflow Authorization Bypass Through User-Controlled Key Vulnerability — Langflow Langflow
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability — JoomShaper SP Page Builder
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability — Microsoft SharePoint Server
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
SimpleHelp Authentication Bypass Vulnerability — SimpleHelp SimpleHelp
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication.
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability — Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.
PTC Windchill and FlexPLM Improper Input Validation Vulnerability — PTC Windchill and FlexPLM
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
Ubiquiti UniFi OS Improper Access Control Vulnerability — Ubiquiti UniFi OS
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
Ubiquiti UniFi OS Path Traversal Vulnerability — Ubiquiti UniFi OS
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
Ubiquiti UniFi OS Improper Input Validation Vulnerability — Ubiquiti UniFi OS
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Lantronix EDS5000 Code Injection Vulnerability — Lantronix EDS5000
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Splunk Enterprise Missing Authentication for Critical Function Vulnerability — Splunk Enterprise
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
Widget Factory Joomla Content Editor Improper Access Control Vulnerability — Widget Factory Joomla Content Editor
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability — Cisco Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability — LiteSpeed cPanel Plugin
LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability — Oracle PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
Ivanti Sentry OS Command Injection Vulnerability — Ivanti Sentry
Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability — Cisco Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability — Arista Extensible Operating System
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability — Google Chromium V8
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Check Point Security Gateway Improper Authentication Vulnerability — Check Point Security Gateway
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
BerriAI LiteLLM Command Injection Vulnerability — BerriAI LiteLLM
BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability — SolarWinds Serv-U
SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication.
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability — Mirasvit Mirasvit Full Page Cache Warmer
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
Android Framework Integer Overflow Vulnerability — Android Framework
Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.
Linux Kernel Improper Authentication Vulnerability — Linux Kernel
Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
Oracle WebLogic Server Unspecified Vulnerability — Oracle WebLogic Server
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability — Palo Alto Networks PAN-OS
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
Daemon Tools Lite Embedded Malicious Code Vulnerability — Daemon Daemon Tools Lite
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
TanStack Unspecified Vulnerability — TanStack TanStack
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
Nx Console Embedded Malicious Code Vulnerability — Nx Nx Console
Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.
LiteSpeed cPanel Plugin Privilege Escalation Vulnerability — LiteSpeed cPanel Plugin
LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.
Drupal Core SQL Injection Vulnerability — Drupal Core
Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability — Trend Micro Apex One
Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
Langflow Origin Validation Error Vulnerability — Langflow Langflow
Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.
Microsoft Defender Denial of Service Vulnerability — Microsoft Defender
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
Microsoft Defender Link Following Vulnerability — Microsoft Defender
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
Microsoft Internet Explorer Use-After-Free Vulnerability — Microsoft Internet Explorer
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Microsoft Internet Explorer Use-After-Free Vulnerability — Microsoft Internet Explorer
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability — Adobe Acrobat and Reader
Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
Microsoft DirectX NULL Byte Overwrite Vulnerability — Microsoft DirectX
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
Recent vulnerabilities by ecosystem
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
js-yaml: Exponential parsing time in flow collections leads to denial of service
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
@fastify/static vulnerable to route guard bypass via path traversal
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Account enumeration via observable login timing discrepancy
Open WebUI: Stored web worker XSS via Pyodide
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Gitea: Webhook Authorization Header Returned in Plaintext via API
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
Eclipse Jetty: Path parameter traversal
Eclipse Jetty: HTTP Authority/Host mismatch
Trix: Stored XSS via HTMLParser attribute injection on paste
Ruby json: JSON generator heap buffer overflow when streaming to an IO
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Loofah: SVG `href` attribute bypasses local-reference restriction
websocket-driver-ruby: Denial of service via malformed Host header
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
Prompty: Arbitrary file read via file reference expansion
nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys
Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion
ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
ImageMagick: Heap Buffer Over-Write in fx operation
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
How fresh is this vulnerability data?
It updates throughout the day. When CISA flags a vulnerability as actively exploited, or a new advisory lands for an npm or PyPI package, it shows up here the same day — usually within the hour. Exploitation-probability (EPSS) scores refresh daily.
What is the CISA KEV (Known Exploited Vulnerabilities) catalog?
It's the US government's list of vulnerabilities that attackers are actively exploiting in the real world — not theoretical risks, but ones with confirmed attacks behind them. Federal agencies are required to patch anything on it by a deadline. If a CVE is on this list, treat it as urgent.
What does an EPSS score actually tell me?
EPSS is a probability: the chance a vulnerability will actually be exploited in the next 30 days, from 0 to 100%. It cuts through the noise — most CVEs are never exploited, and EPSS helps you spot the small handful that likely will be, so you can fix those first.
CVSS, EPSS, KEV — what's the difference, and which matters?
They answer different questions. CVSS tells you how damaging a vulnerability would be if exploited (severity, 0–10). EPSS tells you how likely it is to be exploited soon. KEV tells you it already is. A scary CVSS score on its own doesn't mean you're in danger — pair it with a high EPSS or a KEV listing and you know what to patch today.
Which package ecosystems are covered?
All the major ones — npm, PyPI, Go, Maven, RubyGems, crates.io (Rust) and NuGet — plus everything else tracked by OSV, and vendor software CVEs from the National Vulnerability Database. If a CVE or GitHub advisory exists, you can pull it up here.
How do I look up a specific CVE?
Just add the ID to the address: o3.security/vulnerability/CVE-2021-44228, for instance. GitHub (GHSA) advisory IDs work the same way. You'll get the severity, which packages and products are affected, whether it's being exploited, and how to fix it — all on one page.
Where does the data come from?
From the sources security teams already trust: OSV and the GitHub Advisory Database for open-source packages, the National Vulnerability Database for vendor software, CISA's KEV catalog for active exploitation, and FIRST.org for EPSS. O3 brings them together and adds reachability analysis, so you can see which of these actually reach your code.
Find these CVEs in your own code
O3 Security's Impact-Aware SCA correlates every CVE against your dependency graph and confirms whether the vulnerable code path is actually reachable — so you patch what matters, not the whole list.
Impact-Aware SCA