Skip to content
Noroxi
Live data · 386,105 records · updated Sep 29, 2026

CVE tracking.What comes first?

We combine CVSS, CISA KEV and EPSS into a single action score. Pick your stack, filter to what affects you, follow it and get notified on change.

Action score · 0–100

CVSS
40
Technical severity
KEV
30
Exploited in the wild
EPSS
30
30-day probability

80 and above: now · 60–79: this week · 40–59: plan · below 40: monitor

Total records
386,105
Actively exploited (KEV)
1,729
Weaponized
4,366
Fix today
460
Last 7 days
2,895

Watch your stack · no account needed

What technologies do you use?

Pick them and we’ll filter the live database down to the CVEs that affect you.

Popular picks

Results appear here once you pick a technology.

18 technologies · matched against vendor/product records

Filters
Severity
Exploit status
Attack profile · Tags derived automatically from the CVSS vector, CWE and text; pick several and all must match.
More tags
0

You’re seeing every CVE. Add your stack to narrow the list down to the ones that affect you.

25 of 10,000+ records

  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    apache · log4jDec 10, 2021

  • In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    ivanti · connect secureMay 8, 2019

  • PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    paloaltonetworks · pan-osApr 12, 2024

  • Authentication bypass using an alternate path or channel

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    connectwise · screenconnectFeb 21, 2024

  • An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    ivanti · standalone sentryJun 9, 2026

  • Improper Control of Generation of Code in jai-ext

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    geosolutionsgroup · jai-extApr 13, 2022

  • A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    microsoft · windows 10 1903Mar 12, 2020

  • A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    facebook · reactDec 3, 2025

  • Craft CMS Allows Remote Code Execution

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    craftcms · craft cmsApr 25, 2025

  • An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    gitlab · gitlabApr 23, 2021

  • Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    cisco · ios xeOct 16, 2023

  • Unauthenticated arbitrary file read and remote code execution in CrushFTP

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    crushftp · crushftpApr 22, 2024

  • It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape

    CriticalCVSS 10.0KEVWeaponizedEPSS 99%

    redis · redisFeb 18, 2022

  • Erlang/OTP SSH Vulnerable to Pre-Authentication RCE

    CriticalCVSS 10.0KEVWeaponizedEPSS 99%

    erlang · erlang\/otpApr 16, 2025

  • In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence data centerJun 3, 2022

  • Certain WSO2 products allow unrestricted file upload with resultant remote code execution.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    wso2 · api managerApr 18, 2022

  • Cisco HyperFlex HX Command Injection Vulnerabilities

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    cisco · hyperflex hx data platformMay 6, 2021

  • HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    microsoft · windows 7Apr 14, 2015

  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    sophos · web applianceApr 4, 2023

  • The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · vcenter serverMay 26, 2021

  • The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · cloud foundationSep 23, 2021

  • All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence data centerOct 31, 2023

  • This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    papercut · papercut mfApr 20, 2023

  • In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    atlassian · confluence data centerAug 30, 2021

Have a CVE or analysis to share?

Share detection methods, affected versions, or remediation details. Our team reviews every submission and credits you by name.

Contribute