CVE Tools
6 new critical

The CVE database that answers back.

Discover what's hijacking Splunk Enterprise

42,735Critical
1,623CISA KEV
65,358With Exploits
50,425Nuclei Templates

A live database of 340.7K vulnerabilities — 65.4K linked to public exploit code and 1.6K confirmed exploited (CISA KEV). Continuously synced from NVD, GHSA, CISA KEV, and CSAF advisories — enriched with EPSS scores, exploit links, Nuclei templates, and MITRE ATT&CK mappings. Search, analyze, and query everything through an AI assistant.

Get Started — Free
340.7K
Total CVEs
Accepted into database
42.7K
Critical
CVSS ≥ 9.0
65.4K
With Exploits
Linked to PoC or exploit code
1.6K
In CISA KEV
Known Exploited Vulnerabilities
17.0K
High EPSS
Exploit probability > 10%
50.4K
Nuclei Templates
Scanner templates linked to CVEs

All numbers are live. Our sync pipeline pulls vulnerability data from CVEProject, NVD, GHSA, CISA KEV, CSAF advisories, and other authoritative sources — enriched and scored automatically.

June 2026
in numbers

One snapshot of where vulnerabilities moved this month — volume, severity, KEV velocity, top vendors and CWEs. New report on the 1st.

Open monthly report
3,780
— YoY · proj
215
7.4% of total · so far
10
CISA known exploited
-48.7%
projected MoM
projected — month still in progress

What's discussed now

The CVEs the security world is talking about right now — ranked, with why they matter.

All news
Media lag: median 37d after CVE publication · 3 covered before it was published

See what's inside

From a searchable database with deep filters to an AI analyst you can talk to — every screen is built for security teams that need answers fast.

apache authentication bypass⌘K
847 results
CVE IDVendor / ProductCVSSEPSSFlags
CVE-2025-21298
Microsoft
Windows OLE
9.894.2%
KEVEXPNUC
CVE-2025-0282
Ivanti
Connect Secure
9.089.1%
KEVEXPNUC
CVE-2024-55591
Fortinet
FortiOS SSL-VPN
9.676.3%
KEVNUC
CVE-2024-49113
Apache
Struts 2.x
8.141.7%
EXP
CVE-2024-47575
Fortinet
FortiManager
9.888.0%
KEVEXP
CVE-2024-38094
Microsoft
SharePoint Server
7.237.5%
KEVEXP
847 results · page 1 of 85
12385

Find exploitable CVEs
in seconds, not hours

250,000+ CVEs with a sidebar packed with filters. Combine KEV status, exploit availability, EPSS range, CWE, vendor, attack vector, and date range. Sub-50ms results via Typesense.

  • Priority heatmap: see the critical/high/medium split before you touch a filter
  • Active filter chips — always know what is applied, remove in one click
  • Faceted counts on every option: "CISA KEV (1,247)" — no empty results
  • Save named presets — reload your daily triage view instantly
Powered by Typesense — sub-50ms full-text + facet search

Everything you need to work with vulnerabilities

CVE Tools is not just a database — it's a complete vulnerability intelligence workstation. Every CVE is enriched, linked, and queryable through multiple interfaces.

CVE Database

Live mirror of the official CVEProject feed with CVSS, affected products, CPEs, and CWE weaknesses.

Exploit Intelligence

Auto-linked PoCs from GitHub, ExploitDB, and Metasploit, with maturity signals on each entry.

Nuclei Templates

Community and AI-generated Nuclei templates mapped to specific CVEs for instant validation.

EPSS Scoring

FIRST.org exploit-probability scores on every CVE. Prioritise by likelihood, not just severity.

CISA KEV Tracking

Live overlay of the Known Exploited Vulnerabilities catalog — what is actively abused and mandated to patch.

CSAF Advisories

CISA CSAF 2.0 advisories for IT and OT/ICS, with remediation guidance and product-level severity.

Attack Surface Graph

Interactive map: products to CVEs to MITRE ATT&CK techniques. See how an attacker would chain it.

AI Assistant

Chat with a security analyst about impact, remediation, detection rules, or any CVE in plain English.

MCP, REST API & CLI

Plug in via MCP (Claude, Cursor), call the REST API from scripts, or run cvetools from your terminal.

Attack surface in real time

This graph is built automatically from the 3 most recent critical CVEs in our database. It maps affected products through vulnerabilities to MITRE ATT&CK techniques and kill chain stages — showing not just what's broken, but how it could be exploited.

Latest Critical CVEs & Attack Paths

CVE-2026-128669.8

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled in...

T1190 Exploit Public-Facing ApplicationT1059 Command and Scripting Interpreter
CVE-2026-487469.1

vllm-project/vllm

vLLM: OpenAI auth bypass

T1557 Adversary-in-the-Middle
CVE-2026-113749.0

zohocorp/manageengine_adaudit_plus

Account Takeover via Predictable SSO Ticket Generation

T1110 Brute ForceT1190 Exploit Public-Facing ApplicationT1078 Valid Accounts

This graph updates automatically when new critical CVEs are discovered and enriched.

Where the data comes from

CVE Tools aggregates, enriches, and structures vulnerability data from authoritative sources. Every record passes through our parsing, scoring, and enrichment pipeline before entering the database.

CVEProject / cvelistV5
2h ago
354.2K

Official CVE database from CVE Numbering Authorities. Synced from GitHub repository.

NVD
2h ago
359.8K

NIST National Vulnerability Database. CVSS scoring, CPE matching, and CWE classification.

BDU FSTEC
5d ago
89.5K

Russian FSTEC vulnerability database. Independent severity assessments and remediation data.

GHSA
2h ago
32.2K

GitHub Security Advisories. OSV-format advisories with ecosystem-specific impact data.

Nuclei Templates
6h ago
115.6K

ProjectDiscovery scanner templates. Actionable detection rules linked to CVEs.

CISA CSAF
1d ago
3.8K

CISA CSAF 2.0 advisories for IT and OT/ICS. Industrial control systems security guidance.

CISA KEV
2h ago
1.6K

CISA Known Exploited Vulnerabilities catalog. Confirmed active exploitation in the wild.

More sources

OSV, VulnDB, and ZDI integrations are in development. Suggest a source you'd like to see next.

Total source records956.8K

Years of vulnerability data, continuously growing

Coverage from 1999 to present, by publication year. The current year updates in real time as new vulnerabilities are published and synced.

2021
20,544
2022
25,235
2023
29,006
2024
40,026
2025
46,883
2026
31,531

Ready to dive in?

Everything you just scrolled through is live data. Sign in to search it, query it with AI, and plug it into your tools. No credit card required.

Search the full database AI assistant on every CVE REST API & MCP access