VulnSea

Trends

Aggregate statistics across the VulnSea dataset — refreshed as new CVEs are ingested.

30253
Tracked CVEs
2958
Critical
375
Exploited
309
CISA KEV
2797
PoC available
167
0day
12647
High
5293
Last 7 days

Most talked about

Bluesky + Hacker News mentions, last 7 days
  1. 1CVE-2026-85046High· 8.8Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page74
  2. 2CVE-2026-58704High· 8.8In Cellular Modem, there is a possible permission bypass due to a logic error in the code73
  3. 3CVE-2026-69836Critical· 10.0Microsoft Entra ID Remote Code Execution Vulnerability67
  4. 4CVE-2026-66747Critical· 9.8Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line66
  5. 5CVE-2026-18963Critical· 9.1A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak63

Rising exploit probability

Biggest EPSS jumps in the last 14 days — where exploitation risk is climbing fastest.

New CVEs per month

Last 12 months (by publish date)

101112010203040506070809

Severity distribution

critical
2958
high
12647
medium
10693
low
1382
none
2573

Most-affected vendors

Most-affected ecosystems

From GitHub Advisory package data