Total CVEs
341,116
Last 7 Days
1,732
Critical
16,535
High
113,726

Top Threats

CVE-2021-44228
HIGH CVSS 10.0 KEV nuclei
120 /100
CVE-2025-53770
CRITICAL CVSS 9.8 KEV nuclei
115 /100
CVE-2025-53770
CRITICAL CVSS 9.8 KEV nuclei
115 /100
CVE-2025-53770
CRITICAL CVSS 9.8 KEV nuclei
115 /100
CVE-2020-5902
HIGH CVSS 9.8 KEV nuclei
113 /100
CVE-2022-26134
HIGH CVSS 9.8 KEV nuclei
111 /100
CVE-2021-41773
MEDIUM CVSS 9.8 KEV nuclei
111 /100
CVE-2019-11510
HIGH CVSS 10.0 KEV nuclei
110 /100
CVE-2020-0796
HIGH CVSS 10.0 KEV nuclei
110 /100
CVE-2019-11510
CRITICAL CVSS 9.9 KEV nuclei
110 /100
CVE-2021-42013
HIGH CVSS 9.8 KEV nuclei
109 /100
CVE-2019-0604
HIGH CVSS 9.8 KEV nuclei
108 /100
CVE-2024-3400
CRITICAL CVSS 10.0 KEV nuclei
108 /100
CVE-2024-3400
CRITICAL CVSS 10.0 KEV nuclei
108 /100
CVE-2025-31161
CRITICAL CVSS 9.8 KEV nuclei
107 /100

Exploited in the Wild

CVE-2025-53521
F5 BIG-IP
CVE-2026-33634
Aquasecurity Trivy
CVE-2026-33017
Langflow Langflow
CVE-2025-54068
Laravel Livewire
CVE-2025-43510
Apple Multiple Products
CVE-2025-32432
Craft CMS Craft CMS
CVE-2025-31277
Apple Multiple Products
CVE-2025-43520
Apple Multiple Products
CVE-2026-20131 ransomware
Cisco Secure Firewall Management Center (FMC)
CVE-2025-66376
Synacor Zimbra Collaboration Suite (ZCS)

New Exploit Code

dangerous repositories view all
CVE-2026-2406 malicious 1.00
obrunolima1910/CVE-2026-24061
renamed_interpreter · CV_3.6.zip/compiler.exe is a renamed LuaJIT binary (852 KB, sha256:8b42ca9d05ba)
interpreter_with_payload · CV_3.6.zip/compiler.exe (LuaJIT) loads payload: dynasm.txt (301 KB)
CVE-2026-27940 malicious 1.00
ngtuonghung/CVE-2026-27940
nested_archive_with_scripts · llama.cpp-b8145.zip contains scripts: win-build-sycl.bat, win-run-llama2.bat, win-test.bat, install…
bat_launches_exe · llama.cpp-b8145.zip/win-run-llama2.bat launches: completion.exe
CVE-2026-3891 malicious 1.00
vladimirmanylobed451/CVE-2026-3891
nested_archive_with_scripts · woocommerce.10.6.1.zip contains scripts: wp.bat
obfuscated_script · woocommerce.10.6.1.zip/5875.js (110 KB): extremely long lines, base64 payload (564 chars)
CVE-2023-22515 malicious 1.00
getdrive/PoC
obfuscated_script · CVE-2023-46747-RCE.py (15 KB): base64 payload (864 chars)
doc_links_to_exe · README.md links to executable downloads: http://target_ip:port/%24%7bclass.forname%28%22com.opensym…
CVE-2026-25253 malicious 1.00
ZhaoymOvO/openclaw-1click-rce-env
doc_links_to_exe · exe-dev.md links to executable downloads: https://clawdbot.exe
doc_links_to_archive · hetzner.md links to archive downloads: https://github.com/steipete/gog/releases/latest/download/gog…
CVE-2021-33044 malicious 1.00
nasimanpha-create/ing-switch
renamed_interpreter · ing-switch-3.7.zip/load.exe is a renamed LuaJIT binary (852 KB, sha256:167b166e26dd)
nested_archive_with_exe · ing-switch-3.7.zip contains executables: load.exe (852 KB)
CVE-2025-5548 malicious 1.00
JSantos1990/CVE-2025-5548
exe_in_media_folder · ImmunityDebugger_1_85_setup.zip (22131 KB) hidden in resources/ folder
exe_in_media_folder · Setup_Environment_Windows.ps1 (52 KB) hidden in resources/ folder
CVE-2025-5548 malicious 1.00
luisyapura/Analisis-y-Explotacion-de-CVE-2025-5548
nested_archive_with_exe · ImmunityDebugger_1_85_setup.zip contains executables: ImmunityDebugger_1_85_setup.exe (22216 KB)
nested_archive_with_exe · FreeFloatFtpServer1.0.zip contains executables: ftpserver.exe (18 KB), FTPServer.exe (56 KB), ftpse…
CVE-2020-5902 malicious 1.00
34zY/APT-Backpack
c2_strings_in_exe · CVE-2021-22006.zip/cve-2021-22005_exp_win.exe: keylogger capability
c2_strings_in_exe · ngrok-v3-stable-windows-386.zip/ngrok.exe: keylogger capability
CVE-2020-5902 malicious 1.00
zhzyker/exphub
obfuscated_script · cve-2019-7238_cmd.py (9 KB): base64 payload (6108 chars)
obfuscated_script · cve-2021-26295_rce.py (16 KB): base64 payload (13126 chars)