Live Exploited Vulnerability Feed
Evidence-backed KEV intelligence enriched with confidence scoring, exploitation status, CISA KEV status, and sensor telemetry.
| CVE | Product | Vendor | Confidence | Exploitation Status | Sensors | First Seen | Added | Artifacts |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55182 | react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel | Meta | Confirmed | Active exploitation | — | 17 days ago | 17 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-3055 | ADC, Gateway | NetScaler | Confirmed | Active exploitation | — | 17 days ago | 17 days ago |
PoC
Nuclei
Scanner
|
| CVE-2025-1302 | jsonpath-plus | JSONPath-Plus | Medium | Active exploitation | — | 17 days ago | 17 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-34197 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ | Apache Software Foundation | Confirmed | Active exploitation | — | 17 days ago | 17 days ago |
PoC
Nuclei
Scanner
|
| CVE-2025-68645 | Zimbra Collaboration (ZCS) | Zimbra | Confirmed | Active exploitation | — | 17 days ago | 17 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-0257 | Cloud NGFW, PAN-OS, Prisma Access | Palo Alto Networks | Confirmed | Active exploitation | — | 19 days ago | 19 days ago |
PoC
Nuclei
Scanner
|
| CVE-2025-58360 | geoserver | geoserver | Confirmed | Active exploitation | — | 19 days ago | 19 days ago |
PoC
Nuclei
Scanner
|
| CVE-2025-61882 | Oracle Concurrent Processing | Oracle Corporation | Confirmed | Active exploitation | — | 20 days ago | 20 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-35616 | FortiClientEMS | Fortinet | Confirmed | Active exploitation | — | 20 days ago | 20 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-21643 | FortiClientEMS | Fortinet | Confirmed | Active exploitation | — | 21 days ago | 21 days ago |
PoC
Nuclei
Scanner
|
| CVE-2020-7796 | Zimbra Collaboration Suite | Zimbra | Confirmed | Active exploitation | — | 21 days ago | 21 days ago |
PoC
Nuclei
Scanner
|
| CVE-2025-6205 | DELMIA Apriso | Dassault Systèmes | Confirmed | Active exploitation | — | 21 days ago | 21 days ago |
PoC
Nuclei
Scanner
|
| CVE-2025-25257 | FortiWeb | Fortinet | Confirmed | Active exploitation | — | 21 days ago | 21 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-45321 | arktype-adapter, eslint-plugin-router, eslint-plugin-start, history, nitro-v2-vite-plugin, react-router, react-router-devtools, react-router-ssr-query, react-start, react-start-client, react-start-rsc, react-start-server, router-cli, router-core, router-devtools, router-devtools-core, router-generator, router-plugin, router-ssr-query-core, router-utils, outer-vite-plugin, solid-router, solid-router-devtools, solid-router-ssr-query, solid-start, solid-start-client, solid-start-server, start-client-core, start-fn-stubs, start-plugin-core, start-server-core, start-static-server-functions, start-storage-context, valibot-adapter, virtual-file-routes, vue-router, vue-router-devtools, vue-router-ssr-query, vue-start, vue-start-client, vue-start-server, zod-adapter | @tanstack | Confirmed | Active exploitation | — | 21 days ago | 21 days ago |
PoC
|
| CVE-2018-9205 | avatar_uploader | Robbin Zhao | Medium | Active exploitation | — | 22 days ago | 22 days ago |
PoC
Nuclei
Scanner
|
| CVE-2022-2414 | Dogtag Certificate System | Dogtag PKI | Medium | Exploited | — | 23 days ago | 23 days ago |
PoC
Nuclei
Scanner
|
| CVE-2022-0948 | Order Listener for WooCommerce – Play Sounds Instantly on New Orders | Unknown | Medium | Active exploitation | — | 23 days ago | 23 days ago |
PoC
Nuclei
Scanner
|
| CVE-2022-0785 | Daily Prayer Time | Unknown | Medium | Active exploitation | — | 23 days ago | 23 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-5426 | KnowledgeDeliver | Digital Knowledge | Medium | Active exploitation | — | 24 days ago | 24 days ago |
PoC
|
| CVE-2026-42945 | NGINX Plus, NGINX Open Source | F5 | Medium | Active exploitation | — | 29 days ago | 29 days ago |
PoC
|
| CVE-2026-44338 | PraisonAI | MervinPraison | Medium | Active exploitation | — | about 1 month ago | about 1 month ago |
PoC
Nuclei
Scanner
|
| CVE-2025-34023 | Karel IP Phone IP1211 | Karel | Medium | Active exploitation | — | about 1 month ago | about 1 month ago |
PoC
Nuclei
Scanner
|
| CVE-2018-11409 | Splunk | Splunk | Medium | Active exploitation | — | about 1 month ago | about 1 month ago |
PoC
Nuclei
Scanner
|
| CVE-2024-6893 | Journyx (jtime) | Journyx | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|
| CVE-2025-34509 | Experience Manager, Experience Platform | Sitecore | Medium | Active exploitation | — | about 2 months ago | about 2 months ago |
PoC
Nuclei
Scanner
|