Live analysis of 302,730 vulnerabilities
Total CVEs
All timeCVEs This Year
2026 YTDCVE Velocity
per dayTotal KEVs
Exploited in WildHistorical volume by year (2000 - Present)
Criticality evolution over time
Vulnerability volume acceleration (2000 - Present)
Most affected (Last 30 Days)
KEV additions by year
Attack Vectors (Last 30 Days)
Recently Exploited Vulnerabilities
React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.
SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution.
GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.
Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to potentially obtain remote access to the system as an asterisk user.
Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.
View Full CISA CatalogCurrent Year Analysis
Common CWEs (Last 30 Days)
Data sources: NVD (National Vulnerability Database) and CISA KEV.
CVEDatabase.com provides this analytics dashboard for informational purposes.