Latest Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
374,014 CVEs tracked
55,581 with exploits
5,176 exploited in wild
1,662 CISA KEV
4,294 Nuclei templates
56,669 vendors
50,179 researchers
Investigate
Reference Indexes
CVE-2026-41702: Forty-Seven Microseconds in /var/run/vmware/cnx-tmp
May 17, 2026
Hermes Agent with EIP Harness: The Vulnerability Research Assistant That Also Runs Your Pipelines
May 13, 2026
CVE-2026-41940: cPanel & WHM Pre-Auth RCE - Two Write Paths, One Filter
May 01, 2026
EIP STIX 2.1 / TAXII 2.1 Feed: Exploit Intelligence for Your Stack
Apr 29, 2026
CVE-2026-35414: Three Bugs, One Commit, and Two More Nobody Mentioned
Apr 03, 2026
WP Google Map Plugin - Three Weak Links, One Critical Chain
Mar 29, 2026
View all posts →
CVE-2026-66914
CRITICAL
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1
CVE-2026-62242
HIGH
Spring Boot Admin Server < 4.1.2 SSRF via Unauthenticated Instance Registration
CVE-2026-45829
CRITICAL
ChromaDB >=1.0.0 - Unauthenticated Remote Code Execution via Malicious Model Repository
CVE-2026-42859
HIGH
Neat VNC: Buffer overflow due to oversized RSA public keys
CVE-2026-3296
CRITICAL
Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata
CVE-2026-34980
HIGH
OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
CVE-2026-35414
MEDIUM
OpenSSH < 10.3 - Always-Incorrect Control Flow Implementation in Authorized Keys Principals Handling
CVE-2026-33765
CRITICAL
Pi-hole Web <6.0 savesettings.php - Command Injection
CVE-2026-4105
MEDIUM
Red Hat Enterprise Linux 10 - Improper Access Control via systemd-machined RegisterMachine D-Bus Method
CVE-2026-30861
CRITICAL
WeKnora 0.2.5-0.2.9 - Unauthenticated Remote Code Execution via MCP stdio Configuration Validation Bypass
View all labs →
CVE-2026-20316
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
CVE-2026-16812
VeloCloud Orchestrator OS Command Injection
CVE-2025-68686
Fortinet FortiOS <7.6.1 - Info Disclosure
CVE-2021-27137
Dd-wrt < 45724 - Stack-based Buffer Overflow
CVE-2023-4346
KNX Connection Authorization - Device Lockout Denial of Service
CVE-2026-56155
Microsoft Windows 10 Version 1607 - Active Directory Federation Services Elevation of Privilege Vulnerability
CVE-2026-12569
PTC Windchill PDMLink and FlexPLM - Deserialization Remote Code Execution
CVE-2026-34909
Ubiquiti INC UniFi OS Server - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-48027
Compromised Nx Console version 18.95.0
CVE-2026-8398
DAEMON Tools Lite 12.5.0.2421-12.5.0.2434 - Embedded Malicious Code in Trojanized Installer
CVE-2009-1537
Microsoft DirectX 7.0-9.0c - Remote Code Execution via QuickTime Movie Parser Filter
CVE-2026-6973
Ivanti Endpoint Manager Mobile < 12.6.1.1, < 12.7.0.1, < 12.8.0.1 - Authenticated Remote Code Execution