See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 22:05 UTC 8 of 8 sources healthy

Known exploited

76–90 of 208 matching entries · 3062 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2025-48384KEVGit Link Following Vulnerability0.06 Sep 202622:00 UTCGitSee original advisory1633 sourcesCandidateYesCVE-2025-38352KEVLinux vulnerability7.88 Sep 202616:17 UTCLinux0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 78a4b8e3795b31dae58762bc091bb0f4f74a2200 (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before c076635b3a42771ace7d276de8dc3bc76ee2ba1b (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 2f3daa04a9328220de46f0d5c919a6c0073a9f0b (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 764a7a5dfda23f69919441f2eac2a83e7db6e5bb (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before c29d5318708e67ac13c1b6fc1007d179fb65b4d7 (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 460188bc042a3f40f72d34b9f7fc6ee66b0b757b (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before f90fff1e152dedf52b932240ebbd670d83330eca (git); 2.6.36214 sourcesVerifiedYesCVE-2025-33073KEVMicrosoft Windows SMB Client Improper Access Control Vulnerability8.824 Aug 202621:01 UTCWindowsSee original advisory380 sourcesVerifiedYesCVE-2025-32756KEVFortinet Multiple Products Stack-Based Buffer Overflow Vulnerability9.85 Sep 202612:39 UTCMultiple ProductsSee original advisory91 sourcesCandidateYesCVE-2025-32463KEVSudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability9.34 Sep 202616:04 UTCSudoSee original advisory3305 sourcesVerifiedYesCVE-2025-32433KEVErlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability10.05 Sep 202604:27 UTCErlang/OTPSee original advisory469 sourcesCandidateYesCVE-2025-32432KEVCraft CMS Code Injection Vulnerability0.013 Sep 202622:00 UTCCraft CMSSee original advisory206 sourcesVerifiedYesCVE-2025-31324KEVSAP NetWeaver Unrestricted File Upload Vulnerability0.05 Sep 202622:00 UTCNetWeaverSee original advisory880 sourcesCandidateYesCVE-2025-31161KEVCrushFTP Authentication Bypass Vulnerability9.825 Aug 202602:25 UTCCrushFTPSee original advisory258 sourcesVerifiedYesCVE-2025-31125KEVVite Vitejs Improper Access Control Vulnerability7.58 Sep 202614:40 UTCVitejsSee original advisory100 sourcesCandidateYesCVE-2025-25257KEVFortinet FortiWeb SQL Injection Vulnerability9.84 Sep 202606:47 UTCFortiWebSee original advisory338 sourcesVerifiedYesCVE-2025-25249KEVFortiSwitchManager vulnerability8.110 Sep 202610:47 UTCFortiSwitchManager7.2.2 through 7.2.5 (semver); 7.6.0 through 7.6.2 (semver); 7.4.0 through 7.4.7 (semver); 7.2.4 through 7.2.11 (semver); before * (custom)60 sourcesVerifiedYesCVE-2025-24893KEVXWiki Platform Eval Injection Vulnerability9.813 Sep 202618:34 UTCPlatformSee original advisory100 sourcesVerifiedYesCVE-2025-24813KEVApache Tomcat Path Equivalence Vulnerability10.011 Sep 202622:00 UTCTomcatSee original advisory1137 sourcesVerifiedYesCVE-2025-24054KEVMicrosoft Windows NTLM Hash Disclosure Spoofing Vulnerability6.55 Sep 202608:16 UTCWindowsSee original advisory1063 sourcesVerifiedYes

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.