Vulnerability intelligence
Look up a host or CVE397.5k
CVEs tracked
+13
New in last 24h
1,732
Known exploited (KEV)
28.2k
With public exploits
2,269 new in 7 days · 12,791 in 30 days · 46,679 with EPSS exploitation scores
Exposure
Where these vulnerabilities actually live: hosts running software with known CVEs, measured across the public internet.
169.4M
Hosts observed
29.0M
Hosts with open services
3.6M
Hosts with known CVEs
235
Countries
Most widespread CVEsAffected hosts
Most common softwareHosts
01openssh6,439,507
02nginx2,826,478
03akamaighost1,812,529
04apache1,129,996
05awselb805,692
06cloudfront524,513
07mysql276,196
08cloudflare254,145
09caddy234,451
10microsoft-iis232,457
Most exposed portsHosts
018015,198,083
0244313,361,819
03228,836,288
048443935,735
058080899,549
0621879,792
07161463,854
087547460,940
0925376,810
103306366,715
Countries by exposed hostsHosts
01US6,940,883
02DE2,742,935
03CN2,567,093
04SE1,718,518
05GB1,384,205
06NL1,192,264
07FR979,534
08JP731,962
09KR704,156
10FI703,599
cached · Updated 2026-10-04 18:45 UTC
Severity distribution
Critical39,681
High149,824
Medium169,526
Low15,479
None22,996
CVSS score distribution
How the corpus spreads across CVSS base-score bands (0–10).
CVEs over time
New CVEs published each month since 2000 — total volume with the critical share overlaid.
Total Critical
Actively exploited
The signals that matter for prioritisation: real-world exploitation, not just theoretical severity.
Highest exploitation probability (EPSS)
CVE-2019-19781100%
CVE-2021-21985100%
CVE-2021-26855100%
CVE-2021-34473100%
CVE-2021-40438100%
CVE-2021-44228100%
CVE-2021-45105100%
CVE-2023-0669100%
CVE-2023-35078100%
CVE-2023-44487100%
Recently published known-exploited
CVE-2026-1042869.82026-10-01
CVE-2026-1024899.82026-09-30
CVE-2026-1024909.82026-09-30
CVE-2026-765049.82026-09-30
CVE-2026-869508.82026-09-28
CVE-2026-887719.82026-09-27
CVE-2026-887728.12026-09-27
CVE-2026-879028.12026-09-22
CVE-2026-936169.82026-09-22
CVE-2026-9395210.02026-09-22
Top weakness types (CWE)
01Cross-site Scripting (XSS)47,447
02SQL Injection20,813
03Out-of-bounds Write14,891
04Improper Restriction of Memory Buffer14,325
05Improper Input Validation13,288
06Exposure of Sensitive Information11,084
07Path Traversal10,339
08Missing Authorization10,012
09Out-of-bounds Read9,728
10Cross-Site Request Forgery (CSRF)9,710
11Use After Free8,700
12Improper Access Control7,569
Most affected vendors
01microsoft27,019
02linux22,532
03google16,830
04apple15,243
05oracle11,979
06debian10,220
07ibm9,181
08adobe7,708
09cisco6,798
10redhat6,118
11fedoraproject5,444
12canonical4,327