CVE Data Dashboard

Live analysis of 302,730 vulnerabilities

Last Updated: 2/7/2026 06:00 AM
302,730

Total CVEs

All time
6,259

CVEs This Year

2026 YTD
KEV Velocity
0.61
165

CVE Velocity

per day
This Year
23
1,507

Total KEVs

Exploited in Wild

Publication Trends

Historical volume by year (2000 - Present)

321
1,438
1,323
1,691
1,223
1,612
6,708
6,885
7,322
5,673
5,732
4,639
4,150
5,288
5,142
7,948
6,494
6,457
16,512
17,308
18,375
20,161
25,059
28,961
40,077
49,972
6,259
2000
2001
2002
2003
2004
2005
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026

Historical Severity

Criticality evolution over time

YoY Growth

Vulnerability volume acceleration (2000 - Present)

Top Vendors

Most affected (Last 30 Days)

Microsoft
M
Microsoft
15000
Google
G
Google
8000
Apple
A
Apple
5000
Linux
L
Linux
4000
Oracle
O
Oracle
3500

Exploitation Timeline

KEV additions by year

Threat Landscape

Attack Vectors (Last 30 Days)

Attack Vector

local100
network484
adjacent17
physical2

Active Threats

Recently Exploited Vulnerabilities

CVE-2025-119532/5/2026
React Native Community - CLI

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

CVE-2026-244232/5/2026
SmarterTools - SmarterMail

SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution.

CVE-2021-399352/3/2026
GitLab - Community and Enterprise Editions

GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.

CVE-2025-643282/3/2026
Sangoma - FreePBX

Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to potentially obtain remote access to the system as an asterisk user.

CVE-2019-190062/3/2026
Sangoma - FreePBX

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.

View Full CISA Catalog

Severity Distribution

Current Year Analysis

6,259Total CVEs

Top Weakness Types

Common CWEs (Last 30 Days)

Data sources: NVD (National Vulnerability Database) and CISA KEV.

CVEDatabase.com provides this analytics dashboard for informational purposes.