Trends
Aggregate statistics across the VulnSea dataset — refreshed as new CVEs are ingested.
30253
Tracked CVEs
2958
Critical
375
Exploited
309
CISA KEV
2797
PoC available
167
0day
12647
High
5293
Last 7 days
Most talked about
Bluesky + Hacker News mentions, last 7 days- 1CVE-2026-85046High· 8.8Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page874
- 2CVE-2026-58704High· 8.8In Cellular Modem, there is a possible permission bypass due to a logic error in the code373
- 3CVE-2026-69836Critical· 10.0Microsoft Entra ID Remote Code Execution Vulnerability267
- 4CVE-2026-66747Critical· 9.8Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line266
- 5CVE-2026-18963Critical· 9.1A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak263
Rising exploit probability
Biggest EPSS jumps in the last 14 days — where exploitation risk is climbing fastest.
CVE-2026-58644Critical· 9.8Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.16% → 61%+45 ptsCVE-2026-20079Critical· 10.0A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …36% → 76%+40 ptsCVE-2026-85706Critical· 10.0GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the Gi…1% → 15%+13 ptsCVE-2026-55040Critical· 9.1Microsoft SharePoint Server Security Feature Bypass Vulnerability40% → 51%+11 ptsCVE-2026-42018High· 7.5Anonymous user token generation exposure in JFrog Artifactory0% → 11%+11 pts
New CVEs per month
Last 12 months (by publish date)
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
Severity distribution
critical
2958
high
12647
medium
10693
low
1382
none
2573
Most-affected vendors
Most-affected ecosystems
From GitHub Advisory package data