State now. Changed: +1022 tier promotions, 0 known-exploited vulnerability additions, 1443 leak-site claims, and 0 confirmed breaches since yesterday.
All CVEs
Browse tracked Common Vulnerabilities and Exposures (CVE) identifiers by priority tier, with confirmed exploitation and ransomware evidence visible.
Every tracked Common Vulnerabilities and Exposures (CVE) identifier, ranked into priority tiers. A Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) listing or other confirmed exploitation never ranks below Act. Ransomware association reaches Act now; active exploitation can also rise one tier through either the end-of-life or open-exposure modifier.
Why now: this site build includes 1,704 actively exploited records; the ranked details below show their evidence and actions.
Choose your reading level
The page address stays the same, and this choice follows you to other pages.
Analyst view shows the full table.
State now
962 tracked CVEs are in the Act now tier in this site build.
Why these records matter
- CVE-2026-63077: Exploit Prediction Scoring System probability jumped · 2026-10-05
- CVE-2026-19490: Exploit Prediction Scoring System probability jumped · 2026-10-05
- CVE-2026-104286: Added to the CISA Known Exploited Vulnerabilities catalog · 2026-10-01; Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-10-01; Exploitation status turned active · 2026-10-01
- CVE-2026-88779: Added to the CISA Known Exploited Vulnerabilities catalog · 2026-10-04; Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-10-04; Exploitation status turned active · 2026-10-04
- CVE-2024-49766: Added to the VulnCheck Known Exploited Vulnerabilities catalog · 2026-09-30
What changed
This page does not publish a page-specific change count. Filter recent material changesor scan the daily comparison.
Details
The legend explains every priority and status label, and the filters sit beside the ranked records below.
Federal remediation deadline backlog
Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) due dates are federal agency deadlines and a useful planning signal for every defender. Select a bar to open its matching rows.
Cloud provider flaws that never receive a CVE identifier.
Release cycles past End of Life. No patch is coming.
Compromised and typosquatted packages.
Advisories for operational technology and industrial control systems.
Vendor patches, cross-vendor. Microsoft, Adobe, Cisco, Android.
Public exploit code and proof-of-concepts.
An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.
The change in EPSS since the reading from seven days earlier, in percentage points (a move from 2 percent to 5 percent is +3 percentage points, not +150 percent). Readings are recorded daily, so the comparison is normally exactly seven days old; if ingest was interrupted, the nearest retained reading up to fourteen days back is used instead. Each row states the age of the reading it actually used, so an interrupted week is visible rather than hidden. A CVE with no retained prior reading in that window reads "no prior reading", never a zero or a dash, since either could be misread as no movement.
What each badge means
- No signal currently raises the record above the baseline tier.
- A public exploit, elevated exploitation probability, or Stakeholder-Specific Vulnerability Categorization (SSVC) verdict raises this record for closer watching.
- The SSVC-style verdict calls for attention, but no confirmed exploitation signal sets an Act floor.
- Confirmed active exploitation or an SSVC-style Act verdict requires prompt action.
- Ransomware association sets the top tier; active exploitation can also rise one tier through the end-of-life or open-exposure modifier.
- Listed in the Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities catalog.
- Listed in the VulnCheck Known Exploited Vulnerabilities catalog as observed exploitation.
- Listed as exploited in the European Union Agency for Cybersecurity European Vulnerability Database.
- The CVE Numbering Authority that assigned or published information for the record.
- An Authorized Data Publisher that adds analysis to a CVE record without replacing the assigner.
- A severity score from the European Union Agency for Cybersecurity European Vulnerability Database, shown while NVD analysis is absent.
- The strongest exploitation state supported by the tracker signals for this vulnerability.
Tiers ascend Track (watch), Track* (a public exploit or a rising exploitation forecast), Attend (act in the normal cycle),Act (confirmed exploitation somewhere), and Act now(ransomware association, or active exploitation raised by the end-of-life or open-exposure modifier). A lower tier can never outrank a higher one. A Mentions count of 0 is a measured zero: the tracker looked and found no coverage, rather than not having looked.
| Changed |
|---|