Vulnerabilities

Vulnerability intelligence

A live view of the global CVE landscape — severity, real-world exploitation signals and trends, aggregated from open vulnerability feeds.

As of 2026-10-04, 3.6M of the 169.4M hosts observed run software with known CVEs, and 29.0M have open services, across 235 countries.

Look up a host or CVE
397.5k

CVEs tracked

+13

New in last 24h

1,732

Known exploited (KEV)

28.2k

With public exploits

2,269 new in 7 days · 12,791 in 30 days · 46,679 with EPSS exploitation scores

Exposure

Where these vulnerabilities actually live: hosts running software with known CVEs, measured across the public internet.

169.4M

Hosts observed

29.0M

Hosts with open services

3.6M

Hosts with known CVEs

235

Countries

Most widespread CVEsAffected hosts
Most common softwareHosts
01openssh6,439,507
02nginx2,826,478
03akamaighost1,812,529
04apache1,129,996
05awselb805,692
06cloudfront524,513
07mysql276,196
08cloudflare254,145
09caddy234,451
10microsoft-iis232,457
Most exposed portsHosts
018015,198,083
0244313,361,819
03228,836,288
048443935,735
058080899,549
0621879,792
07161463,854
087547460,940
0925376,810
103306366,715
Countries by exposed hostsHosts
01US6,940,883
02DE2,742,935
03CN2,567,093
04SE1,718,518
05GB1,384,205
06NL1,192,264
07FR979,534
08JP731,962
09KR704,156
10FI703,599

cached · Updated 2026-10-04 18:45 UTC

Severity distribution

Critical39,681
High149,824
Medium169,526
Low15,479
None22,996

CVSS score distribution

How the corpus spreads across CVSS base-score bands (0–10).

CVEs over time

New CVEs published each month since 2000 — total volume with the critical share overlaid.

Total Critical

Actively exploited

The signals that matter for prioritisation: real-world exploitation, not just theoretical severity.

Highest exploitation probability (EPSS)

CVE-2019-19781100%
CVE-2021-21985100%
CVE-2021-26855100%
CVE-2021-34473100%
CVE-2021-40438100%
CVE-2021-44228100%
CVE-2021-45105100%
CVE-2023-0669100%
CVE-2023-35078100%
CVE-2023-44487100%

Recently published known-exploited

CVE-2026-1042869.82026-10-01
CVE-2026-1024899.82026-09-30
CVE-2026-1024909.82026-09-30
CVE-2026-765049.82026-09-30
CVE-2026-869508.82026-09-28
CVE-2026-887719.82026-09-27
CVE-2026-887728.12026-09-27
CVE-2026-879028.12026-09-22
CVE-2026-936169.82026-09-22
CVE-2026-9395210.02026-09-22

Top weakness types (CWE)

01Cross-site Scripting (XSS)47,447
02SQL Injection20,813
03Out-of-bounds Write14,891
04Improper Restriction of Memory Buffer14,325
05Improper Input Validation13,288
06Exposure of Sensitive Information11,084
07Path Traversal10,339
08Missing Authorization10,012
09Out-of-bounds Read9,728
10Cross-Site Request Forgery (CSRF)9,710
11Use After Free8,700
12Improper Access Control7,569

Most affected vendors

01microsoft27,019
02linux22,532
03google16,830
04apple15,243
05oracle11,979
06debian10,220
07ibm9,181
08adobe7,708
09cisco6,798
10redhat6,118
11fedoraproject5,444
12canonical4,327