Vulnerability intelligence
VULONE Vulnerability Database
Stay ahead of what gets exploited. Every CVE from NVD, enriched every 30 minutes with EPSS, CISA KEV, ransomware linkage and automated analysis.
Filters Show:
Latest CVEs. Most recently published vulnerabilities.
View all| ID | Severity | Score | Technology | Weakness | CISA KEV | Exploit | EPSS | Published |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-101033 | Medium | 5.3 | Not yet mapped | Insecure direct object reference | — | — | — | Sep 27, 2026 |
| CVE-2026-101032 | High | 7.3 | Not yet mapped | OS command injection | — | — | — | Sep 27, 2026 |
| CVE-2026-100872 | High | 8.7 | Not yet mapped | Insufficient verification of data | — | — | — | Sep 27, 2026 |
| CVE-2026-100871 | High | 8.7 | Not yet mapped | Improper authentication | — | — | — | Sep 27, 2026 |
| CVE-2026-100870 | High | 8.7 | Not yet mapped | Weak password recovery | — | — | — | Sep 27, 2026 |
| CVE-2026-100869 | High | 8.2 | Not yet mapped | Incorrect authorization | — | — | — | Sep 27, 2026 |
| CVE-2026-100868 | Medium | 5.3 | Not yet mapped | CWE-1327 | — | — | — | Sep 27, 2026 |
| CVE-2026-100867 | Medium | 4.8 | Not yet mapped | CWE-150 | — | — | — | Sep 27, 2026 |
| CVE-2026-100866 | Medium | 4.8 | Not yet mapped | CWE-150 | — | — | — | Sep 27, 2026 |
| CVE-2026-97165 | Medium | 5.3 | Not yet mapped | Cross-site scripting | — | — | — | Sep 27, 2026 |
| CVE-2026-97164 | High | 7.0 | Not yet mapped | Path traversal | — | — | — | Sep 27, 2026 |
| CVE-2026-100749 | Medium | 5.1 | Not yet mapped | Cross-site request forgery | — | — | — | Sep 27, 2026 |
Exploited in the wild. Newest additions to the CISA Known Exploited Vulnerabilities catalog.
View all| ID | Severity | Score | Technology | Weakness | CISA KEV | Exploit | EPSS | KEV added |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65660 | High | 8.8 | Code injection | Listed | Confirmed | 2.1% | Sep 25, 2026 | |
| CVE-2026-87902 | High | 8.1 | WordPress Core Remote File Inclusion Vul | PHP remote file inclusion | Listed | Confirmed | 18% | Sep 25, 2026 |
| CVE-2026-67279 | Medium | 6.9 | CWE-841 | Listed | Confirmed | 1.0% | Sep 25, 2026 | |
| CVE-2026-5430 | Critical | 10.0 | Improper verification of cryptogra | Listed | Confirmed | 0.59% | Sep 24, 2026 | |
| CVE-2026-71362 | Critical | 9.1 | Incorrect authorization | Listed | Confirmed | 88% | Sep 24, 2026 | |
| CVE-2026-85102 | Critical | 9.8 | Improper certificate validation | Listed | Confirmed | 0.99% | Sep 22, 2026 | |
| CVE-2026-93616 | Critical | 9.8 | Path traversal | Listed | Confirmed | 20% | Sep 22, 2026 | |
| CVE-2026-93952 | Critical | 9.5 | Improper input validation | Listed | Confirmed | 0.90% | Sep 22, 2026 |
Most likely to be exploited. Highest EPSS probability among CVEs published in the last six months.
View all| ID | Severity | Score | Technology | Weakness | CISA KEV | Exploit | EPSS | Published |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-10520 | Critical | 10.0 | OS command injection | Listed | Confirmed | 100% | Jun 9, 2026 | |
| CVE-2026-41940 | Critical | 9.3 | Missing authentication for critica | Listed · RW | Confirmed | 99% | Apr 29, 2026 | |
| CVE-2026-20253 | Critical | 9.8 | Missing authentication for critica | Listed | Confirmed | 97% | Jun 10, 2026 | |
| CVE-2026-0257 | High | 7.8 | Reliance on cookies without valida | Listed · RW | Confirmed | 96% | May 13, 2026 | |
| CVE-2026-20182 | Critical | 10.0 | Improper authentication | Listed | Confirmed | 92% | May 14, 2026 | |
| CVE-2026-85706 | Critical | 10.0 | Path traversal | Listed | Confirmed | 91% | Sep 12, 2026 | |
| CVE-2026-48908 | Critical | 10.0 | Unrestricted file upload | Listed | Confirmed | 89% | Jun 20, 2026 | |
| CVE-2026-20230 | High | 8.6 | Server-side request forgery (SSRF) | Listed | Confirmed | 88% | Jun 3, 2026 |
Ransomware-linked. Known ransomware use per CISA, or referenced in a crew playbook in the VULONE knowledge base.
View all| ID | Severity | Score | Technology | Weakness | CISA KEV | Exploit | EPSS | KEV added |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-59310 | Critical | 9.8 | Path traversal | Listed · RW | Confirmed | 2.6% | Aug 18, 2026 | |
| CVE-2026-63077 | Critical | 9.8 | Deserialization of untrusted data | Listed · RW | Confirmed | 9.8% | Aug 5, 2026 | |
| CVE-2026-20316 | Medium | 5.3 | Hard-coded password | Listed · RW | Confirmed | 35% | Jul 29, 2026 | |
| CVE-2026-15409 | Critical | 10.0 | Server-side request forgery (SSRF) | Listed · RW | Confirmed | 6.8% | Jul 14, 2026 | |
| CVE-2026-15410 | High | 7.2 | Code injection | Listed · RW | Confirmed | 12% | Jul 14, 2026 | |
| CVE-2026-45659 | High | 8.8 | Deserialization of untrusted data | Listed · RW | Confirmed | 2.7% | Jul 1, 2026 | |
| CVE-2026-12569 | Critical | 9.3 | Improper input validation | Listed · RW | Confirmed | 46% | Jun 25, 2026 | |
| CVE-2026-35273 | Critical | 9.8 | Missing authentication for critica | Listed · RW | Confirmed | 9.4% | Jun 12, 2026 |
Critical. CVSS 9.0 and above, newest first.
View all| ID | Severity | Score | Technology | Weakness | CISA KEV | Exploit | EPSS | Published |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-100741 | Critical | 9.8 | Not yet mapped | CWE-95 | — | — | — | Sep 27, 2026 |
| CVE-2026-100835 | Critical | 9.1 | Not yet mapped | Improper certificate validation | — | — | — | Sep 27, 2026 |
| CVE-2026-100721 | Critical | 9.5 | Not yet mapped | Incorrect authorization | — | — | — | Sep 27, 2026 |
| CVE-2026-82901 | Critical | 9.8 | Not yet mapped | Unrestricted file upload | — | — | — | Sep 26, 2026 |
| CVE-2026-85984 | Critical | 9.8 | Not yet mapped | Improper authentication | — | — | — | Sep 26, 2026 |
| CVE-2026-97163 | Critical | 10.0 | Not yet mapped | Path traversal | — | — | — | Sep 26, 2026 |
| CVE-2026-97161 | Critical | 9.2 | Not yet mapped | Path traversal | — | — | — | Sep 26, 2026 |
| CVE-2026-97160 | Critical | 9.4 | Not yet mapped | Code injection | — | — | — | Sep 26, 2026 |
Most affected vendors. Vulnerable configurations published in the last 12 months.
For your tooling
The same records as JSON.
Filter by KEV, severity, EPSS, vendor and product, poll with since, and pull the ransomware crews, C2 servers and forum chatter that reference each CVE. Or subscribe over TAXII from Sentinel, Splunk, MISP or OpenCTI.
$ curl -H "Authorization: Bearer vul_your_key" \ https://app.vulone.com/api/v1/cve?kev=1&sort=kev { "total": 1,726, "has_more": true, "cves": [ … ] }
Sources: NIST NVD (CVE API 2.0), CISA Known Exploited Vulnerabilities catalog, FIRST EPSS. Automated analyses are generated by VULONE's analysis model and are not human-reviewed.