Live Exploited Vulnerability Feed
Evidence-backed KEV intelligence enriched with confidence scoring, exploitation status, CISA KEV status, and sensor telemetry.
| CVE | Product | Vendor | Confidence | Exploitation Status | Sensors | First Seen | Added | Artifacts |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0948 | Order Listener for WooCommerce – Play Sounds Instantly on New Orders | Unknown | Medium | Active exploitation | — | 23 days ago | 23 days ago |
PoC
Nuclei
Scanner
|
| CVE-2022-0785 | Daily Prayer Time | Unknown | Medium | Active exploitation | — | 23 days ago | 23 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-5426 | KnowledgeDeliver | Digital Knowledge | Medium | Active exploitation | — | 24 days ago | 24 days ago |
PoC
|
| CVE-2025-34048 | DSL-2730U, DSL-2750U, DSL-2750E | D-Link | Medium | Active exploitation | — | 25 days ago | 25 days ago |
—
|
| CVE-2023-7311 | Flow Control Router | BYTEVALUE (Luoyang Baiwei Intelligent Technology Co., Ltd.) | Medium | Active exploitation | — | 27 days ago | 27 days ago |
—
|
| CVE-2026-42945 | NGINX Plus, NGINX Open Source | F5 | Medium | Active exploitation | — | 29 days ago | 29 days ago |
PoC
|
| CVE-2020-11963 | IQrouter | Evenroute | Medium | Active exploitation | — | about 1 month ago | about 1 month ago |
—
|
| CVE-2025-7544 | AC1206 | Tenda | Medium | Active exploitation | — | about 1 month ago | about 1 month ago |
—
|
| CVE-2026-44338 | PraisonAI | MervinPraison | Medium | Active exploitation | — | about 1 month ago | about 1 month ago |
PoC
Nuclei
Scanner
|
| CVE-2025-34023 | Karel IP Phone IP1211 | Karel | Medium | Active exploitation | — | about 1 month ago | about 1 month ago |
PoC
Nuclei
Scanner
|
| CVE-2018-11409 | Splunk | Splunk | Medium | Active exploitation | — | about 1 month ago | about 1 month ago |
PoC
Nuclei
Scanner
|
| CVE-2023-37999 | HT Mega | HasThemes | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|
| CVE-2024-6893 | Journyx (jtime) | Journyx | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|
| CVE-2025-34509 | Experience Manager, Experience Platform | Sitecore | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|
| CVE-2023-0159 | Extensive VC Addons for WPBakery page builder | Unknown | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|
| CVE-2023-25573 | metersphere | metersphere | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|
| CVE-2025-10353 | Melis Platform | Melis Technology | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|
| CVE-2026-3844 | Breeze Cache | cloudways | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|
| CVE-2021-4374 | WordPress Automatic Plugin | ValvePress | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|
| CVE-2026-33626 | lmdeploy | InternLM | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|
| CVE-2019-8451 | Jira | Atlassian | Medium | Exploited | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|
| CVE-2026-25187 | Windows 10 Version 1607, Windows 10 Version 1809, Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 22H3, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 version 26H1, Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | Microsoft | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
—
|
| CVE-2026-3564 | ScreenConnect | ConnectWise | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
—
|
| CVE-2026-26127 | .NET 10.0, .NET 9.0, Microsoft.Bcl.Memory | Microsoft | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
—
|
| CVE-2026-21262 | Microsoft SQL Server 2016 Service Pack 3 (GDR), Microsoft SQL Server 2016 Service Pack 3 Azure Connect Feature Pack, Microsoft SQL Server 2017 (CU 31), Microsoft SQL Server 2017 (GDR), Microsoft SQL Server 2019 (CU 32), Microsoft SQL Server 2019 (GDR), Microsoft SQL Server 2022 (GDR), Microsoft SQL Server 2022 for x64-based Systems (CU 23), Microsoft SQL Server 2025 (CU 2), Microsoft SQL Server 2025 for x64-based Systems (GDR) | Microsoft | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
—
|