cvekit
LIVE

Trending CVEs

last 7d
  • Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

    7.5
    1.00
    over 2 years ago
  • The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

    3.4
    1.00
    almost 12 years ago
  • Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.

    5.9
    1.00
    over 4 years ago
  • CVE-2017-7921CRITICALKEV

    An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.

    9.8
    1.00
    over 9 years ago
  • Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    8.8
    1.00
    about 1 year ago
  • CVE-2025-53770CRITICALKEV

    Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

    9.8
    1.00
    about 1 year ago
  • CVE-2025-3248CRITICALKEV

    Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

    9.8
    1.00
    over 1 year ago
  • Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

    5.3
    1.00
    about 5 years ago
  • CVE-2024-23897CRITICALKEV

    Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

    9.8
    1.00
    over 2 years ago
  • CVE-2024-3400CRITICALKEV

    A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

    10.0
    1.00
    over 2 years ago
  • CVE-2024-3273CRITICALKEV

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

    9.8
    1.00
    over 2 years ago
  • A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

    8.2
    1.00
    over 2 years ago
  • CVE-2023-35082CRITICALKEV

    An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

    9.8
    1.00
    about 3 years ago
  • CVE-2024-21887CRITICALKEV

    A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

    9.1
    1.00
    over 2 years ago
  • CVE-2023-1671CRITICALKEV

    A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

    9.8
    1.00
    over 3 years ago
  • CVE-2023-22518CRITICALKEV

    All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.  Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

    9.8
    1.00
    almost 3 years ago
  • Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

    7.5
    1.00
    almost 3 years ago
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

    7.5
    1.00
    almost 3 years ago
  • Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.

    7.5
    1.00
    over 3 years ago
  • CVE-2023-35078CRITICALKEV

    An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

    9.8
    1.00
    about 3 years ago
  • TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

    8.8
    1.00
    over 3 years ago
  • CVE-2023-27350CRITICALKEV

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

    9.8
    1.00
    over 3 years ago
  • Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

    7.2
    1.00
    over 3 years ago
  • CVE-2022-44877CRITICALKEV

    login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.

    9.8
    1.00
    over 3 years ago
  • CVE-2022-26134CRITICALKEV

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

    9.8
    1.00
    about 4 years ago
  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

    7.5
    1.00
    over 12 years ago
  • CVE-2022-29464CRITICALKEV

    Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

    9.8
    1.00
    over 4 years ago
  • CVE-2022-22954CRITICALKEV

    VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

    9.8
    1.00
    over 4 years ago
  • CVE-2012-1823CRITICALKEV

    sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.

    9.8
    1.00
    over 14 years ago
  • CVE-2019-16920CRITICALKEV

    Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

    9.8
    1.00
    almost 7 years ago

Newest CVEs

by publish date
  • sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse.format(sql, reindent=True) and sqlformat --reindent route attacker-controlled parenthesized tuple lists through ReindentFilter._get_offset() in sqlparse/filters/reindent.py, where _flatten_up_to_token() repeatedly rebuilds and joins the statement prefix. Thousands of offset calculations walk an expanding token tree, producing quadratic CPU consumption for inputs that remain below MAX_GROUPING_TOKENS and causing request delays, reduced throughput, or worker starvation. This issue is fixed in version 0.6.0.

    about 2 hours ago
  • gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.

    about 2 hours ago
  • gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1.

    about 2 hours ago
  • Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.

    7.2
    about 2 hours ago
  • Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious `uri` query parameter to the HTTP API. Attackers can pass arbitrary `tcp://` or `unix://` URIs to affected endpoints including /api/info, /api/speech-to-text, and /api/text-to-speech to override the server-configured backend and redirect connections to attacker-chosen hosts.

    8.3
    about 2 hours ago
  • A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could create, modify, and delete their own project.

    about 2 hours ago
  • A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authentication. If exploited, a threat actor could view customer data.

    about 3 hours ago
  • OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-local core.fsmonitor setting. If a user opens or uses an attacker-prepared repository whose preserved .git/config sets core.fsmonitor to an attacker-controlled filesystem-monitor helper, Git can execute that helper while Codex collects repository metadata. The helper runs outside Codex's command sandbox and without a user-approval prompt, allowing attacker-controlled code to run with the user's privileges. The code can read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the source repository's local .git/config; exploitation requires a repository delivered or copied with that configuration intact.

    about 3 hours ago
  • OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process filter can cause Git to run an attacker-controlled program. The program runs outside Codex's command sandbox with the signed-in user's privileges, without a workspace-trust prompt, command approval, or interaction with a model. The attacker can read, modify, or delete files and access credentials available to that user. Exploitation requires Git to be available on PATH and the user to open the attacker-prepared repository with its local Git configuration intact. An ordinary Git clone does not copy the source repository's .git/config and is not sufficient by itself.

    about 3 hours ago
  • OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex follows its instructions, Codex can run a file-writing Git command without requesting user approval. On macOS and Linux, exploitation additionally requires separately installed PowerShell Core (pwsh) to be invoked. If filesystem protections permit the write, the command can modify Codex's configuration. If Codex later loads the modified configuration, it can launch an attacker-controlled MCP server and execute code with the user's privileges, allowing it to read, change, or delete files accessible to that account. The approval bypass does not disable filesystem sandboxing; the default filesystem sandbox on macOS and Linux can prevent writes outside permitted locations.

    about 3 hours ago
  • OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user opens an attacker-prepared repository whose preserved .git/config points core.hooksPath to an attacker-controlled directory, Codex can run a malicious hook while processing the repository. The hook executes outside Codex's command sandbox, without user approval, and with the user's privileges, allowing it to read, change, or delete the user's files and access other resources available to the user's account. An ordinary Git clone does not preserve the attacker-controlled repository-local configuration required for exploitation.

    about 3 hours ago
  • Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

    8.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago
  • NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

    7.8
    about 4 hours ago

CVSS Score Histogram

247.7k scored
10
34
1.4k
4.1k
21.0k
46.3k
41.2k
64.4k
33.9k
35.3k
0123456789+
lowCVSS base scorehigh

Severity

all tracked
247.6k
total
  • MEDIUM43.8%
  • HIGH39.7%
  • CRITICAL14.2%
  • LOW2.2%
  • NONE0.0%

Top Weaknesses

30 · CWE

Top Vendors

50 · by CVE
  • 1
    microsoft1085p
    26.2k
  • 2
    linux18p
    19.1k
  • 3
    google239p
    16.2k
  • 4
    apple196p
    15.1k
  • 5
    oracle1103p
    12.6k
  • 6
    debian112p
    10.2k
  • 7
    ibm1613p
    8.7k
  • 8
    adobe182p
    7.5k
  • 9
    cisco6283p
    6.7k
  • 10
    redhat541p
    6.2k
  • 11
    fedoraproject20p
    5.4k
  • 12
    canonical60p
    4.3k
  • 13
    mozilla44p
    3.8k
  • 14
    apache388p
    3.4k
  • 15
    opensuse50p
    3.3k
  • 16
    qualcomm3633p
    2.5k
  • 17
    hp17236p
    2.5k
  • 18
    netapp373p
    2.5k
  • 19
    huawei1956p
    2.3k
  • 20
    siemens4181p
    2.2k
  • 21
    tenda218p
    1.8k
  • 22
    jenkins696p
    1.8k
  • 23
    intel9743p
    1.8k
  • 24
    dlink934p
    1.8k
  • 25
    sun200p
    1.7k
  • 26
    samsung2873p
    1.7k
  • 27
    dell3727p
    1.6k
  • 28
    sap429p
    1.6k
  • 29
    gitlab10p
    1.5k
  • 30
    netgear1110p
    1.3k
  • 31
    suse121p
    1.2k
  • 32
    gnu122p
    1.2k
  • 33
    fortinet255p
    1.1k
  • 34
    juniper440p
    1.1k
  • 35
    totolink159p
    1.1k
  • 36
    mediatek593p
    1.1k
  • 37
    phpgurukul87p
    1.1k
  • 38
    vmware196p
    1.0k
  • 39
    f5282p
    1.0k
  • 40
    joomla149p
    976
  • 41
    drupal142p
    864
  • 42
    nvidia359p
    828
  • 43
    imagemagick3p
    806
  • 44
    foxitsoftware24p
    797
  • 45
    schneider-electric1763p
    780
  • 46
    php25p
    780
  • 47
    wireshark1p
    776
  • 48
    oretnom23112p
    761
  • 49
    novell111p
    677
  • 50
    broadcom279p
    660

Top Assigners

50 · CNA
  • 1
    mitre
    115.9k
  • 2
    GitHub_M
    19.0k
  • 3
    Patchstack
    17.3k
  • 4
    VulDB
    15.8k
  • 5
    Linux
    14.9k
  • 6
    redhat
    12.6k
  • 7
    Wordfence
    10.9k
  • 8
    oracle
    9.3k
  • 9
    apple
    8.4k
  • 10
    ibm
    8.4k
  • 11
    microsoft
    7.7k
  • 12
    adobe
    7.6k
  • 14
    VulnCheck
    6.7k
  • 15
    cisco
    6.6k
  • 16
    Chrome
    6.0k
  • 17
    google_android
    5.2k
  • 18
    WPScan
    4.8k
  • 19
    intel
    4.2k
  • 20
    icscert
    3.8k
  • 21
    qualcomm
    3.7k
  • 22
    certcc
    3.5k
  • 23
    zdi
    3.4k
  • 24
    jpcert
    3.2k
  • 25
    mozilla
    2.7k
  • 26
    talos
    2.5k
  • 27
    apache
    2.4k
  • 28
    dell
    2.3k
  • 29
    huawei
    2.3k
  • 30
    fortinet
    1.9k
  • 31
    siemens
    1.9k
  • 32
    hackerone
    1.7k
  • 33
    sap
    1.6k
  • 34
    GitLab
    1.6k
  • 35
    @huntrdev
    1.6k
  • 36
    hpe
    1.6k
  • 38
    jenkins
    1.5k
  • 39
    INCIBE
    1.1k
  • 40
    nvidia
    1.1k
  • 41
    MediaTek
    1.1k
  • 42
    juniper
    1.0k
  • 43
    hp
    986
  • 44
    f5
    964
  • 45
    @huntr_ai
    904
  • 46
    vmware
    899
  • 47
    twcert
    896
  • 48
    snyk
    879
  • 49
    debian
    804
  • 50
    Samsung Mobile
    788

CVE Publish Timeline

last 3 years
161.7k
new CVEs · Sep 2023Sep 2026
148
avg / day
1.5k
peak Jul 2026
Sep 2023Mar 2024Sep 2024Mar 2025Sep 2025Mar 2026Sep 2026
04919821.5k

Top ATT&CK

50 · technique

Top Products

50 · vulnerable
  • 1
    linux kernellinux
    14.8k
  • 2
    debian linuxdebian
    10.0k
  • 3
    androidgoogle
    8.2k
  • 4
    chromegoogle
    6.2k
  • 5
    fedorafedoraproject
    5.4k
  • 6
    windows server 2016microsoft
    5.1k
  • 7
    windows server 2019microsoft
    4.9k
  • 8
    windows server 2012microsoft
    4.2k
  • 9
    iphone osapple
    4.2k
  • 10
    ubuntu linuxcanonical
    4.1k
  • 11
    windows server 2008microsoft
    3.6k
  • 12
    windows server 2022microsoft
    3.3k
  • 13
    firefoxmozilla
    3.3k
  • 14
    mac os xapple
    3.2k
  • 15
    windows 10microsoft
    3.0k
  • 16
    macosapple
    2.9k
  • 17
    windows 10 1809microsoft
    2.5k
  • 18
    windows 10 21h2microsoft
    2.5k
  • 19
    windows 10 22h2microsoft
    2.5k
  • 20
    windows 7microsoft
    2.4k
  • 21
    windows 8.1microsoft
    2.2k
  • 22
    windows 10 1607microsoft
    2.1k
  • 23
    tvosapple
    2.1k
  • 24
    ipadosapple
    2.1k
  • 25
    windows rt 8.1microsoft
    2.0k
  • 26
    enterprise linux desktopredhat
    1.9k
  • 27
    enterprise linuxredhat
    1.9k
  • 28
    windows 11 24h2microsoft
    1.9k
  • 29
    windows server 2025microsoft
    1.9k
  • 30
    leapopensuse
    1.9k
  • 31
    enterprise linux serverredhat
    1.9k
  • 32
    thunderbirdmozilla
    1.9k
  • 33
    enterprise linux workstationredhat
    1.8k
  • 34
    watchosapple
    1.8k
  • 35
    windows 11 23h2microsoft
    1.8k
  • 36
    acrobat dcadobe
    1.8k
  • 37
    acrobat reader dcadobe
    1.8k
  • 38
    windows server 2022 23h2microsoft
    1.7k
  • 39
    safariapple
    1.7k
  • 40
    windows 11 22h2microsoft
    1.7k
  • 41
    internet explorermicrosoft
    1.6k
  • 42
    opensuseopensuse
    1.5k
  • 43
    gitlabgitlab
    1.4k
  • 44
    acrobatadobe
    1.4k
  • 45
    mysqloracle
    1.3k
  • 46
    windows 10 1507microsoft
    1.2k
  • 47
    wcd9380 firmwarequalcomm
    1.2k
  • 48
    windows 11 25h2microsoft
    1.2k
  • 49
    experience manageradobe
    1.2k
  • 50
    wsa8830 firmwarequalcomm
    1.1k

Exploit Sources

38,920 exploited
  • 1
    Exploitdbexploitdb
    25.1k
  • 2
    Github Pocgithub_poc
    10.7k
  • 3
    Metasploitmetasploit
    3.2k

KEV Velocity

last 14d
17
added · 14d
peak 6
08-26
08-19KEV additions / day09-01
Sources22/22
cisa_kev1,687 / 24habout 17 hours ago·csaf_cisco0 / 24habout 13 hours ago·csaf_oracle0 / 24habout 12 hours ago·csaf_redhat0 / 24h29 minutes ago·csaf_siemens0 / 24habout 13 hours ago·cve.org15,819 / 24h33 minutes ago·EPSS (FIRST.org)366,526 / 24habout 18 hours ago·euvd48,000 / 24h13 minutes ago·exploitdb47,144 / 24habout 15 hours ago·ghsa108 / 24h44 minutes ago·github_poc501,806 / 24h33 minutes ago·metasploit3 days ago·misp3 days ago·mitre_attack3 days ago·mitre_capec3 days ago·mitre_cwe3 days ago·mitre_d3fend3 days ago·msrc0 / 24habout 13 hours ago·NVD API 2.02,530 / 24habout 1 hour ago·osv286,286 / 24habout 16 hours ago·sigma3,757 / 24habout 15 hours ago·vulncheck_kev0 / 24habout 16 hours ago·cisa_kev1,687 / 24habout 17 hours ago·csaf_cisco0 / 24habout 13 hours ago·csaf_oracle0 / 24habout 12 hours ago·csaf_redhat0 / 24h29 minutes ago·csaf_siemens0 / 24habout 13 hours ago·cve.org15,819 / 24h33 minutes ago·EPSS (FIRST.org)366,526 / 24habout 18 hours ago·euvd48,000 / 24h13 minutes ago·exploitdb47,144 / 24habout 15 hours ago·ghsa108 / 24h44 minutes ago·github_poc501,806 / 24h33 minutes ago·metasploit3 days ago·misp3 days ago·mitre_attack3 days ago·mitre_capec3 days ago·mitre_cwe3 days ago·mitre_d3fend3 days ago·msrc0 / 24habout 13 hours ago·NVD API 2.02,530 / 24habout 1 hour ago·osv286,286 / 24habout 16 hours ago·sigma3,757 / 24habout 15 hours ago·vulncheck_kev0 / 24habout 16 hours ago·

Top Threat Actors

drag to browse · all actors →
Storm-1175
Cybercrime

no aliases

CVEs attributed11 KEV-listed
11
UAT-11795
Cybercrime

no aliases

CVEs attributed9 KEV-listed
9
UAT-8616
Cybercrime

no aliases

CVEs attributed6 KEV-listed
6
UAT-8302
Cybercrime

no aliases

CVEs attributed3 KEV-listed
3
Inception Framework
APT
EspionageState-sponsored

aka: ATK116 · Blue Odin · Clean Ursa · Cloud Atlas +2

CVEs attributed3 KEV-listed
3
Dark Caracal
Cybercrime

aka: G0070

CVEs attributed3 KEV-listed
3
INJ3CTOR3
Cybercrime

no aliases

CVEs attributed1 KEV-listed
2
Turla
APT
EspionageState-sponsored

aka: ATK13 · Blue Python · G0010 · Group 88 +22

CVEs attributed2 KEV-listed
2
Belsen Group
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
The Gentlemen
Ransomware

no aliases

CVEs attributed2 KEV-listed
2
Water Sigbin
APT

aka: 8220 Gang

CVEs attributed2 KEV-listed
2
UNC6748
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
Mora_001
Ransomware

no aliases

CVEs attributed2 KEV-listed
2
Shadow-Earth-053
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
ScreamedJungle
Cybercrime

no aliases

CVEs attributed1 KEV-listed
2
UAT-7810
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
Void Blizzard
Cybercrime

aka: LAUNDRY BEAR · Laundry Bear · TA488 · UAC-0190

CVEs attributed2 KEV-listed
2
APT41
APT
State-sponsored

aka: Amoeba · BARIUM · BRONZE ATLAS · BRONZE EXPORT +17

CVEs attributed2 KEV-listed
2
TA459
APT

aka: G0062

CVEs attributed2 KEV-listed
2
SandCat
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
UNC5330
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
Team46
Cybercrime

aka: TaxOff

CVEs attributed1 KEV-listed
2
UNC5337
Cybercrime

no aliases

CVEs attributed2 KEV-listed
2
BRONZE SPIRAL
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
DarkCasino
APT

no aliases

CVEs attributed1 KEV-listed
1
DragonForce
Hacktivist

no aliases

CVEs attributed1 KEV-listed
1
Denim Tsunami
Cybercrime

aka: DSIRF · KNOTWEED

CVEs attributed1 KEV-listed
1
Lilac Typhoon
APT

aka: DEV-0234

CVEs attributed1 KEV-listed
1
Opal Sleet
APT

aka: Konni · OSMIUM · Vedalia

CVEs attributed1 KEV-listed
1
Storm-1567
Ransomware

aka: Akira · GOLD SAHARA · PUNK SPIDER

CVEs attributed1 KEV-listed
1
ProCC
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
UNC5325
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
FlyingYeti
Cybercrime

aka: Flying Yeti · Storm-1837

CVEs attributed1 KEV-listed
1
Void Banshee
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
Earth Baxia
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
CosmicBeetle
Ransomware

no aliases

CVEs attributed1 KEV-listed
1
SongXY
APT

no aliases

CVEs attributed1 KEV-listed
1
Asnarök
Cybercrime

aka: Personal Panda

CVEs attributed1 KEV-listed
1
UNC5820
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
Tstark
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
UAC-0194
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
Ukrainian Cyber Alliance
Ransomware

aka: UCA

CVEs attributed1 KEV-listed
1
Operation ForumTroll
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
UAC-0226
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
Earth Lamia
Cybercrime

aka: UNC5454

CVEs attributed1 KEV-listed
1
UNC6485
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
UAT-8837
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1
DarkPink
APT

aka: Saaiwc

CVEs attributed1 KEV-listed
1
UAT-6382
Cybercrime

no aliases

CVEs attributed
1
Amaranth-Dragon
Cybercrime

no aliases

CVEs attributed1 KEV-listed
1

Live Events

Reconnecting…