CVE tracking.What comes first?
We combine CVSS, CISA KEV and EPSS into a single action score. Pick your stack, filter to what affects you, follow it and get notified on change.
Action score · 0–100
- CVSS
- 40
- Technical severity
- KEV
- 30
- Exploited in the wild
- EPSS
- 30
- 30-day probability
80 and above: now · 60–79: this week · 40–59: plan · below 40: monitor
Watch your stack · no account needed
What technologies do you use?
Pick them and we’ll filter the live database down to the CVEs that affect you.
Popular picks
Results appear here once you pick a technology.
18 technologies · matched against vendor/product records
You’re seeing every CVE. Add your stack to narrow the list down to the ones that affect you.
25 of 10,000+ records
Action = CVSS weight + active exploitation + exploitation probability (0–100).
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2021-44228Weaponized | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Critical10.0 | KEV | 100.0% | Dec 10, 2021 |
100Now | CVE-2019-11510Weaponized | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attackivanti · connect secure · CWE-22 | Critical10.0 | KEV | 100.0% | May 8, 2019 |
100Now | CVE-2024-3400Weaponized | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtectpaloaltonetworks · pan-os · CWE-20 | Critical10.0 | KEV | 100.0% | Apr 12, 2024 |
100Now | CVE-2024-1709Weaponized | Authentication bypass using an alternate path or channelconnectwise · screenconnect · CWE-288 | Critical10.0 | KEV | 100.0% | Feb 21, 2024 |
100Now | CVE-2026-10520Weaponized | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated userivanti · standalone sentry · CWE-78 | Critical10.0 | KEV | 99.9% | Jun 9, 2026 |
100Now | CVE-2022-24816Weaponized | Improper Control of Generation of Code in jai-extgeosolutionsgroup · jai-ext · CWE-94 | Critical10.0 | KEV | 99.9% | Apr 13, 2022 |
100Now | CVE-2020-0796Weaponized | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requemicrosoft · windows 10 1903 · CWE-119 | Critical10.0 | KEV | 99.8% | Mar 12, 2020 |
100Now | CVE-2025-55182Weaponized | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Critical10.0 | KEV | 99.8% | Dec 3, 2025 |
100Now | CVE-2025-32432Weaponized | Craft CMS Allows Remote Code Executioncraftcms · craft cms · CWE-94 | Critical10.0 | KEV | 99.8% | Apr 25, 2025 |
100Now | CVE-2021-22205Weaponized | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.gitlab · gitlab · CWE-94 | Critical10.0 | KEV | 99.7% | Apr 23, 2021 |
100Now | CVE-2023-20198Weaponized | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.cisco · ios xe · CWE-420 | Critical10.0 | KEV | 99.6% | Oct 16, 2023 |
100Now | CVE-2024-4040Weaponized | Unauthenticated arbitrary file read and remote code execution in CrushFTPcrushftp · crushftp · CWE-1336 | Critical10.0 | KEV | 99.5% | Apr 22, 2024 |
100Now | CVE-2022-0543Weaponized | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Critical10.0 | KEV | 99.4% | Feb 18, 2022 |
100Now | CVE-2025-32433Weaponized | Erlang/OTP SSH Vulnerable to Pre-Authentication RCEerlang · erlang\/otp · CWE-306 | Critical10.0 | KEV | 98.8% | Apr 16, 2025 |
99Now | CVE-2022-26134Weaponized | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Critical9.8 | KEV | 100.0% | Jun 3, 2022 |
99Now | CVE-2022-29464Weaponized | Certain WSO2 products allow unrestricted file upload with resultant remote code execution.wso2 · api manager · CWE-22 | Critical9.8 | KEV | 100.0% | Apr 18, 2022 |
99Now | CVE-2021-1498Weaponized | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Critical9.8 | KEV | 100.0% | May 6, 2021 |
99Now | CVE-2015-1635Weaponized | HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote amicrosoft · windows 7 · CWE-94 | Critical9.8 | KEV | 100.0% | Apr 14, 2015 |
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2023-1671Weaponized | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution sophos · web appliance · CWE-77 | Critical9.8 | KEV | 100.0% | Apr 4, 2023 |
99Now | CVE-2021-21985Weaponized | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plvmware · vcenter server · CWE-918 | Critical9.8 | KEV | 100.0% | May 26, 2021 |
99Now | CVE-2021-22005Weaponized | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.vmware · cloud foundation · CWE-22 | Critical9.8 | KEV | 100.0% | Sep 23, 2021 |
99Now | CVE-2023-22518Weaponized | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.atlassian · confluence data center · CWE-863 | Critical9.8 | KEV | 100.0% | Oct 31, 2023 |
99Now | CVE-2023-27350Weaponized | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Critical9.8 | KEV | 100.0% | Apr 20, 2023 |
99Now | CVE-2021-26084Weaponized | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Critical9.8 | KEV | 100.0% | Aug 30, 2021 |
- CVE-2021-44228100Now
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
CriticalCVSS 10.0KEVWeaponizedEPSS 100%apache · log4jDec 10, 2021
- CVE-2019-11510100Now
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack
CriticalCVSS 10.0KEVWeaponizedEPSS 100%ivanti · connect secureMay 8, 2019
- CVE-2024-3400100Now
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
CriticalCVSS 10.0KEVWeaponizedEPSS 100%paloaltonetworks · pan-osApr 12, 2024
- CVE-2024-1709100Now
Authentication bypass using an alternate path or channel
CriticalCVSS 10.0KEVWeaponizedEPSS 100%connectwise · screenconnectFeb 21, 2024
- CVE-2026-10520100Now
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user
CriticalCVSS 10.0KEVWeaponizedEPSS 100%ivanti · standalone sentryJun 9, 2026
- CVE-2022-24816100Now
Improper Control of Generation of Code in jai-ext
CriticalCVSS 10.0KEVWeaponizedEPSS 100%geosolutionsgroup · jai-extApr 13, 2022
- CVE-2020-0796100Now
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque
CriticalCVSS 10.0KEVWeaponizedEPSS 100%microsoft · windows 10 1903Mar 12, 2020
- CVE-2025-55182100Now
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
CriticalCVSS 10.0KEVWeaponizedEPSS 100%facebook · reactDec 3, 2025
- CVE-2025-32432100Now
Craft CMS Allows Remote Code Execution
CriticalCVSS 10.0KEVWeaponizedEPSS 100%craftcms · craft cmsApr 25, 2025
- CVE-2021-22205100Now
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.
CriticalCVSS 10.0KEVWeaponizedEPSS 100%gitlab · gitlabApr 23, 2021
- CVE-2023-20198100Now
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
CriticalCVSS 10.0KEVWeaponizedEPSS 100%cisco · ios xeOct 16, 2023
- CVE-2024-4040100Now
Unauthenticated arbitrary file read and remote code execution in CrushFTP
CriticalCVSS 10.0KEVWeaponizedEPSS 100%crushftp · crushftpApr 22, 2024
- CVE-2022-0543100Now
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
CriticalCVSS 10.0KEVWeaponizedEPSS 99%redis · redisFeb 18, 2022
- CVE-2025-32433100Now
Erlang/OTP SSH Vulnerable to Pre-Authentication RCE
CriticalCVSS 10.0KEVWeaponizedEPSS 99%erlang · erlang\/otpApr 16, 2025
- CVE-2022-2613499Now
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerJun 3, 2022
- CVE-2022-2946499Now
Certain WSO2 products allow unrestricted file upload with resultant remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%wso2 · api managerApr 18, 2022
- CVE-2021-149899Now
Cisco HyperFlex HX Command Injection Vulnerabilities
CriticalCVSS 9.8KEVWeaponizedEPSS 100%cisco · hyperflex hx data platformMay 6, 2021
- CVE-2015-163599Now
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · windows 7Apr 14, 2015
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2023-167199Now
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%sophos · web applianceApr 4, 2023
- CVE-2021-2198599Now
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check pl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · vcenter serverMay 26, 2021
- CVE-2021-2200599Now
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · cloud foundationSep 23, 2021
- CVE-2023-2251899Now
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerOct 31, 2023
- CVE-2023-2735099Now
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%papercut · papercut mfApr 20, 2023
- CVE-2021-2608499Now
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerAug 30, 2021
Have a CVE or analysis to share?
Share detection methods, affected versions, or remediation details. Our team reviews every submission and credits you by name.