Live Exploited Vulnerability Feed
Evidence-backed KEV intelligence enriched with confidence scoring, exploitation status, CISA KEV status, and sensor telemetry.
| CVE | Product | Vendor | Confidence | Exploitation Status | Sensors | First Seen | Added | Artifacts |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-48907 | Joomla Content Editor (JCE) extension for Joomla | joomlacontenteditor.net | Confirmed | Active exploitation | — | 2 days ago | 2 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-39813 | FortiSandbox, FortiSandbox Cloud | Fortinet | High | Active exploitation | Yes | 2 days ago | 2 days ago |
PoC
|
| CVE-2026-53435 | Jenkins | Jenkins Project | High | Active exploitation | — | 2 days ago | 2 days ago |
PoC
|
| CVE-2026-20253 | Splunk Enterprise | Splunk | High | Active exploitation | Yes | 3 days ago | 3 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager | Cisco | Confirmed | Active exploitation | — | 3 days ago | 3 days ago |
PoC
|
| CVE-2026-54420 | cPanel Plugin | LiteSpeed Technologies | Confirmed | Active exploitation | — | 4 days ago | 4 days ago |
PoC
|
| CVE-2026-39808 | FortiSandbox, FortiSandbox PaaS | Fortinet | High | Active exploitation | Yes | 5 days ago | 5 days ago |
PoC
Nuclei
Scanner
|
| CVE-2021-31805 | Apache Struts | Apache Software Foundation | High | Active exploitation | Yes | 6 days ago | 6 days ago |
PoC
Nuclei
Scanner
|
| CVE-2020-6286 | SAP NetWeaver AS JAVA (LM Configuration Wizard) | SAP SE | High | Active exploitation | Yes | 6 days ago | 6 days ago |
PoC
|
| CVE-2026-35273 | PeopleSoft Enterprise PeopleTools | Oracle Corporation | Confirmed | Active exploitation | Yes | 6 days ago | 6 days ago |
PoC
|
| CVE-2026-5027 | langflow | langflow-ai | High | Active exploitation | — | 7 days ago | 7 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-10520 | Sentry | ivanti | Confirmed | Active exploitation | Yes | 7 days ago | 7 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-11645 | Chrome | Confirmed | Active exploitation | — | 8 days ago | 8 days ago |
PoC
|
|
| CVE-2026-34910 | UniFi OS Server, UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, UDM-Beast, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UNVR, UNVR-Pro, UNVR-Instant, UNVR-G2, UNVR-G2-Pro, ENVR, ENVR-Core, UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4, UNAS-Pro-8, UCKP, UCK, UCK-Enterprise, UCG-Ultra, UCG-Max, UCG-Fiber, UCG-Industrial | Ubiquiti Inc | High | Active exploitation | Yes | 9 days ago | 9 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-42271 | litellm | BerriAI | Confirmed | Active exploitation | — | 9 days ago | 9 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-50751 | Quantum Security Gateway, Spark Firewalls | checkpoint | Confirmed | Active exploitation | — | 9 days ago | 9 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-28318 | Serv-U | SolarWinds | Confirmed | Active exploitation | — | 12 days ago | 12 days ago |
PoC
|
| CVE-2026-7473 | EOS | Arista Networks | Confirmed | Active exploitation | — | 12 days ago | 12 days ago |
PoC
|
| CVE-2026-3300 | Everest Forms Pro | WPEverest | High | Active exploitation | — | 12 days ago | 12 days ago |
PoC
Nuclei
Scanner
|
| CVE-2026-20245 | Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager | Cisco | Confirmed | Active exploitation | — | 13 days ago | 13 days ago |
PoC
|
| CVE-2026-45247 | Full Page Cache Warmer for Magento 2 | Mirasvit | Confirmed | Active exploitation | — | 14 days ago | 14 days ago |
PoC
|
| CVE-2022-0492 | kernel | Linux | Confirmed | Active exploitation | — | 15 days ago | 15 days ago |
PoC
Scanner
|
| CVE-2025-48595 | Android | Confirmed | Active exploitation | — | 15 days ago | 15 days ago |
—
|
|
| CVE-2026-41089 | Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation), Windows Server 2016, Windows Server 2016 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Windows Server 2022, Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows Server 2025 (Server Core installation) | Microsoft | High | Active exploitation | — | 15 days ago | 15 days ago |
PoC
|
| CVE-2024-21182 | WebLogic Server | Oracle Corporation | Confirmed | Active exploitation | — | 16 days ago | 16 days ago |
PoC
|