Vulnerability Database
Curated CVE records with CVSS severity, EPSS exploit probability, and CISA KEV exploitation status. All KEV entries, plus high-signal CVEs from 2026 onward.
Actively Exploited (CISA KEV)
ProFTPD Improper Access Control Vulnerability
ISC BIND Data Processing Errors Vulnerability
Apache Struts Command Injection Vulnerability
ONLYOFFICE Docs Server Path Traversal Vulnerability
Strapi Cleartext Storage of Sensitive Information Vulnerability
Memory overflow vulnerability leading to Denial of Service
Highest Exploit Probability
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability
osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read
REC in MCPJam inspector due to HTTP Endpoint exposes
Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload
Recently Published
Memory overflow vulnerability leading to Denial of Service
Fortinet FortiMail Path Traversal Vulnerability
Local privilege escalation in Zammad v1.5.0 to v7.2.2 installed via DEB or RPM package
Undisclosed RCE in Zammad v6.3 and higher
Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability
Apple Multiple Products Out-of-Bounds Write Vulnerability
Browse by Vendor
Browse by Weakness
Browse by Port
Named Vulnerabilities
37About This Vulnerability Database
This vulnerability database is built from three public data sources: the official CVE List for record data, the CISA KEV catalog for confirmed exploitation, and FIRST EPSS for exploitation probability. Records update on a daily sync.
Each record shows the CVSS base score from the assigning CNA or CISA, the EPSS percentile, affected vendor and product versions, and references grouped by type. KEV entries additionally carry the federal remediation due date and the required action CISA publishes.
Frequently Asked Questions
What is a vulnerability database?→
A vulnerability database collects records of publicly disclosed security flaws, identified by CVE IDs, with severity scores, affected products, and references. This database focuses on exploited and high-probability CVEs rather than every published record.
What is the CISA Known Exploited Vulnerabilities catalog?→
The CISA KEV catalog lists CVEs confirmed as exploited in the wild. US federal agencies must remediate listed vulnerabilities by a set due date, and the catalog is widely used as a remediation priority signal outside government.
What is an EPSS score?→
EPSS (Exploit Prediction Scoring System) is a FIRST-maintained model that estimates the probability a CVE will be exploited in the next 30 days. Scores range from 0 to 1 and update daily as new threat data arrives.
Which vulnerabilities are included in this database?→
- +Every CVE listed in the CISA KEV catalog, regardless of publication year.
- +CVEs with a 2026-or-later ID and an EPSS score of 0.1 or higher.
- +CVEs with a 2026-or-later ID, an exploit-tagged reference, and an EPSS score of 0.05 or higher.
How often is this vulnerability database updated?→
Records sync daily from the CVE List, the CISA KEV catalog, and FIRST EPSS. New KEV additions and EPSS score changes appear on the next sync.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). Coverage: all CISA KEV entries, plus exploitation-signaled CVEs from 2026 onward. This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.