51.7K+ CVEs enriched with EPSS, CISA KEV, CERT-FR, MSRC, GHSA, Exploit-DB, and Nuclei. Public REST API, free tier available.
NVD-backed, continuously synced
CISA KEV catalog ∪ SSVC=active
Severity = CRITICAL, published in window
FIRST exploit-prediction probability
Refreshed every 30 minutes from production database
Recent high-severity CVEs straight from our PostgreSQL catalog — with KEV, EPSS, and exploitation flags inline.
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally al…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a craft…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplyi…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying…
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining…
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can…
Same database, different cuts. Each list is a real query against cveCatalog at request time.
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
No unauthenticated RCEs flagged yet.
Nine upstream sources, one normalized record per CVE.
Base CVE record + CVSS v3 scores and vectors
Known Exploited Vulnerabilities catalog with due dates
FIRST exploit-prediction score and percentile
French national CSIRT advisories with severity
Microsoft Security Response Center title + KB articles
GitHub Security Advisories cross-references
Public proof-of-concept and exploit identifiers
Detection-template availability flag
Change-log titles and history counts
Continuous CPE-based monitoring with KEV / EPSS prioritization for the products you actually run.
Combine CVSS, EPSS, and KEV signals to rank which CVEs deserve emergency change windows.
Block pull requests when a dependency surfaces a high-EPSS or KEV-flagged CVE in the bulk API.
Export filtered CVE lists with CERT-FR / KEV / GHSA links for audit packets.
Stable public pages for CVEs with exploitation, KEV, EPSS, or severity signals useful during vendor and patch-risk research.
The full NVD CVE catalog from 1999 to present is ingested with continuous backfill, and the count above reflects the live row count in our PostgreSQL store. We enrich each record with CISA KEV, EPSS, CERT-FR, MSRC, GHSA, Exploit-DB, Nuclei template availability, and OpenCVE change history when available.
Daily NVD sync plus EPSS daily snapshots, CISA KEV refresh, and external enrichment cron jobs. The most recent CVEs typically land within a few hours of NVD publication.
A CVE is shown as actively exploited when at least one of these is true: it appears in the CISA KEV catalog, FIRST has classified its SSVC exploitation level as "active", or our GCVE (Google CVE) enrichment has confirmed in-the-wild exploitation evidence.
CVSS measures intrinsic severity (impact × exploitability). EPSS measures the empirical probability that a CVE will be exploited in the wild within the next 30 days, based on global telemetry. We surface both — most teams prioritize on EPSS × KEV first, then CVSS for ties.
Yes. The Free plan (€0, no credit card) includes 30 reputation/CVE checks per month with rate-limited API access. Pro (€99/mo) raises that to 10,000 and includes bulk, downloadable blocklists, AI-generated assessment, the SSE stream, webhooks, and STIX/TAXII.
Yes — that is what CVE Watch is for. You define perimeters of CPE strings (the products and versions you run) and we continuously match new CVEs to those perimeters. Alerts are delivered via dashboard, email, webhook, or the SSE stream.
The /api/cve and /api/cve/recent endpoints are publicly accessible (rate-limited) so you can integrate without an API key for low-volume usage. Higher-volume access requires registration and a free or paid plan.
Every CVE in the catalog gets a stable canonical page at https://ismalicious.com/cve/CVE-YYYY-NNNNN with full metadata, JSON-LD, and links to the original NVD/KEV/CERT-FR/MSRC/GHSA references.
Free API key, 30 checks/month, no credit card. Bulk and stream endpoints available on Pro.