Vulnerability Intelligence Hub
Real-time CVE monitor & vulnerability analyzer — CVSS scores, CISA KEV, exploitation status and security advisories.
Severity distribution
18,388
Critical (CVSS 9.0–10)
69,038
High (CVSS 7.0–8.9)
83,277
Medium (CVSS 4.0–6.9)
9,688
Low (CVSS 0.1–3.9)
1,655
Active entries in CISA KEV
332
KEV with known ransomware use
- Critical 10.2%
- High 38.3%
- Medium 46.2%
- Low 5.4%
Latest 10 published CVEs
| CVE ID | Date | Sev. | Target |
|---|---|---|---|
| CVE-2026-58150 | 2026-07-29 | 10.0 |
Apache Software Foundation
Apache Traffic Server
|
| CVE-2026-57834 | 2026-07-29 | 10.0 |
Apache Software Foundation
Apache Traffic Server
|
| CVE-2026-33930 | 2026-07-29 | 5.9 |
Apache Software Foundation
Apache Traffic Server
|
| CVE-2026-24033 | 2026-07-29 | 7.2 |
Apache Software Foundation
Apache Traffic Server
|
| CVE-2026-33267 | 2026-07-29 | 10.0 |
Apache Software Foundation
Apache Traffic Server
|
| CVE-2026-22068 | 2026-07-29 | 8.2 |
Apache Software Foundation
Apache Traffic Server
|
| CVE-2026-41920 | 2026-07-29 | 9.3 |
Apache Software Foundation
Apache Traffic Server
|
| CVE-2026-35226 | 2026-07-29 | 6.5 |
CODESYS
CODESYS PROFINET
|
| CVE-2026-18197 | 2026-07-29 | 6.4 |
—
Link Library
|
| CVE-2026-18192 | 2026-07-29 | 6.5 |
Vacron
VIN-DS783E-E6
|
Latest added to CISA KEV
| CVE ID | Added | Due date | Ransomware |
|---|---|---|---|
| CVE-2026-16812 | 2026-07-27 | 2026-07-30 | — |
| CVE-2025-68686 | 2026-07-27 | 2026-08-10 | — |
| CVE-2026-50522 | 2026-07-22 | 2026-07-25 | — |
| CVE-2026-16232 | 2026-07-22 | 2026-07-25 | — |
| CVE-2021-27137 | 2026-07-21 | 2026-07-24 | — |
| CVE-2026-0770 | 2026-07-21 | 2026-07-24 | — |
| CVE-2026-63030 | 2026-07-21 | 2026-07-24 | — |
| CVE-2026-60137 | 2026-07-21 | 2026-08-04 | — |
| CVE-2026-39808 | 2026-07-16 | 2026-07-19 | — |
| CVE-2026-25089 | 2026-07-16 | 2026-07-19 | — |
Top 25 by CVSS score
| # | CVE ID | Score | Severity | Vendor | Product | CWE | Exploitation | Published |
|---|---|---|---|---|---|---|---|---|
| 1 | CVE-2026-58150 | 10.0 | CRITICAL | Apache Software Foundation | Apache Traffic Server | CWE-444 | — | 2026-07-29 |
| 2 | CVE-2026-57834 | 10.0 | CRITICAL | Apache Software Foundation | Apache Traffic Server | CWE-444 | — | 2026-07-29 |
| 3 | CVE-2026-33267 | 10.0 | CRITICAL | Apache Software Foundation | Apache Traffic Server | CWE-20 | — | 2026-07-29 |
| 4 | CVE-2026-16498 | 10.0 | CRITICAL | HashiCorp | Tooling | CWE-488 | — | 2026-07-28 |
| 5 | CVE-2026-65880 | 10.0 | CRITICAL | balbooa.com | Balbooa Forms component for Joomla | CWE-94 | — | 2026-07-28 |
| 6 | CVE-2026-11756 | 10.0 | CRITICAL | Dassault Systèmes | Station Launcher App in 3DEXPERIENCE… | CWE-502 | — | 2026-07-28 |
| 7 | CVE-2026-16812 | 10.0 | CRITICAL | Arista Networks | VeloCloud Orchestrator On-Prem | CWE-78 | ACTIVE | 2026-07-27 |
| 8 | CVE-2026-66012 | 10.0 | CRITICAL | siyuan-note | siyuan | CWE-862 | PoC | 2026-07-25 |
| 9 | CVE-2026-56163 | 10.0 | CRITICAL | Microsoft | Azure Kubernetes Service | CWE-306 | — | 2026-07-24 |
| 10 | CVE-2026-58630 | 10.0 | CRITICAL | Microsoft | Azure App Service for Linux | CWE-284 | — | 2026-07-24 |
| 11 | CVE-2026-57106 | 10.0 | CRITICAL | Microsoft | Microsoft Purview Data Governance | CWE-918 | — | 2026-07-24 |
| 12 | CVE-2026-58275 | 10.0 | CRITICAL | Microsoft | Azure DNS | CWE-862 | — | 2026-07-24 |
| 13 | CVE-2026-62825 | 10.0 | CRITICAL | Microsoft | Azure Key Vault | CWE-287 | — | 2026-07-24 |
| 14 | CVE-2026-56191 | 10.0 | CRITICAL | Microsoft | Microsoft Exchange Online | CWE-287 | — | 2026-07-24 |
| 15 | CVE-2026-42933 | 10.0 | CRITICAL | Pronetiqs | Panduit Intravue | CWE-441 | — | 2026-07-23 |
| 16 | CVE-2025-71389 | 10.0 | CRITICAL | calcom | cal.diy | CWE-94 | — | 2026-07-23 |
| 17 | CVE-2026-47668 | 10.0 | CRITICAL | dbgate | dbgate | CWE-20 | PoC | 2026-07-23 |
| 18 | CVE-2026-6516 | 10.0 | CRITICAL | Zohocorp | ManageEngine ADAudit Plus | CWE-78 | — | 2026-07-23 |
| 19 | CVE-2026-64812 | 10.0 | CRITICAL | JetBrains | IntelliJ IDEA | CWE-306 | — | 2026-07-23 |
| 20 | CVE-2026-64813 | 10.0 | CRITICAL | JetBrains | IntelliJ IDEA | CWE-602 | — | 2026-07-23 |
| 21 | CVE-2026-59555 | 10.0 | CRITICAL | Roland Barker | Participants Database | CWE-22 | — | 2026-07-23 |
| 22 | CVE-2026-60366 | 10.0 | CRITICAL | Oracle Corporation | Oracle Platform Security for Java | CWE-502 | — | 2026-07-22 |
| 23 | CVE-2026-60644 | 10.0 | CRITICAL | Oracle Corporation | Oracle WebCenter Content | CWE-306 | — | 2026-07-21 |
| 24 | CVE-2026-60389 | 10.0 | CRITICAL | Oracle Corporation | Service Delivery Platform | CWE-306 | — | 2026-07-21 |
| 25 | CVE-2026-60379 | 10.0 | CRITICAL | Oracle Corporation | Service Delivery Platform | CWE-306 | — | 2026-07-21 |