Vulnerabilities
Which software flaws matter right now — 381,848 CVEs tracked daily, scored by exploitation probability, cross-checked against the 1,674 CISA has confirmed exploited.
Last updated: 23 August 2026 00:24 UTC
Act
Today's briefthe day's signal decomposed into to-dos — filter, check off, exportToday's signalnew KEV entries, biggest EPSS movers, fresh criticals — rankedDaily CVE trackerevery recent CVE plotted by exploitation probabilityRisk scoring explainedhow the 0–100 composite score worksExplore
Weakness patterns (CWE)748 weakness classes, blind spots flaggedAI-software vulnerabilitiesthe AI/ML attack surface, tracked dailyEU vs NVD severitywhere European CSIRTs disagree with NVDEUVD criticalswhat ENISA rates critical right nowUnderstand
Is the problem growing?publication volume, severity distribution, and re-scored CVEs over timeLLMs discovering vulnerabilitieshow AI models are changing disclosureMythos Hype Indexmeasuring the AI-discovery signal against the noiseHow will attackers react?the offense-side analysis of LLM discoveryRecent news — Vulnerabilities
- KEV: CVE-2026-0770 — Langflow Langflow (Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability)
- KEV: CVE-2026-72898 — Metabase Metabase (Metabase SQL Injection Vulnerability)
- KEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)
- Patch bundle: July 2026 Security Updates — 1164 CVEs, 3 exploited
- KEV: CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) (Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability)
- KEV: CVE-2026-16812 — Arista VeloCloud Orchestrator (Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability)