See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 22:05 UTC 8 of 8 sources healthy

Known exploited

76–90 of 213 matching entries · 2884 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2025-67038KEVEDS5000 series vulnerability9.38 Sep 202617:00 UTCEDS5000 series0 through 2.1.0.0R3 (custom); before 2.6.0.4R6 (custom); before 3.21.0.0R1 (custom)33 sourcesNoneYesCVE-2025-62593KEVRay-Project Ray Code Injection Vulnerability0.016 Aug 202622:00 UTCRaySee original advisory2 sourcesNoneYesCVE-2025-57819KEVSangoma FreePBX Authentication Bypass Vulnerability10.02 Sep 202622:00 UTCFreePBXSee original advisory609 sourcesVerifiedYesCVE-2025-49113KEVRoundCube Webmail Deserialization of Untrusted Data Vulnerability9.911 Sep 202618:32 UTCWebmailSee original advisory100 sourcesVerifiedYesCVE-2025-48384KEVGit Link Following Vulnerability0.06 Sep 202622:00 UTCGitSee original advisory1504 sourcesCandidateYesCVE-2025-38352KEVLinux vulnerability7.88 Sep 202616:17 UTCLinux0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 78a4b8e3795b31dae58762bc091bb0f4f74a2200 (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before c076635b3a42771ace7d276de8dc3bc76ee2ba1b (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 2f3daa04a9328220de46f0d5c919a6c0073a9f0b (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 764a7a5dfda23f69919441f2eac2a83e7db6e5bb (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before c29d5318708e67ac13c1b6fc1007d179fb65b4d7 (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 460188bc042a3f40f72d34b9f7fc6ee66b0b757b (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before f90fff1e152dedf52b932240ebbd670d83330eca (git); 2.6.36190 sourcesVerifiedYesCVE-2025-33073KEVMicrosoft Windows SMB Client Improper Access Control Vulnerability8.824 Aug 202621:01 UTCWindowsSee original advisory332 sourcesVerifiedYesCVE-2025-32756KEVFortinet Multiple Products Stack-Based Buffer Overflow Vulnerability9.85 Sep 202612:39 UTCMultiple ProductsSee original advisory85 sourcesCandidateYesCVE-2025-32463KEVSudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability9.34 Sep 202616:04 UTCSudoSee original advisory3083 sourcesVerifiedYesCVE-2025-32433KEVErlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability10.05 Sep 202604:27 UTCErlang/OTPSee original advisory304 sourcesCandidateYesCVE-2025-32432KEVCraft CMS Code Injection Vulnerability0.013 Sep 202622:00 UTCCraft CMSSee original advisory144 sourcesVerifiedYesCVE-2025-31324KEVSAP NetWeaver Unrestricted File Upload Vulnerability0.05 Sep 202622:00 UTCNetWeaverSee original advisory814 sourcesCandidateYesCVE-2025-31161KEVCrushFTP Authentication Bypass Vulnerability9.825 Aug 202602:25 UTCCrushFTPSee original advisory243 sourcesVerifiedYesCVE-2025-31125KEVVite Vitejs Improper Access Control Vulnerability7.58 Sep 202614:40 UTCVitejsSee original advisory91 sourcesCandidateYesCVE-2025-25257KEVFortinet FortiWeb SQL Injection Vulnerability9.84 Sep 202606:47 UTCFortiWebSee original advisory317 sourcesVerifiedYes

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.