Statistics
Catalogue aggregates over time. Last sync Oct 8, 2026
Share of catalog CVEs with a current CVSS score
- CRITICAL 42,743 (11%)
- HIGH 156,889 (39%)
- MEDIUM 171,294 (42%)
- LOW 12,250 (3%)
- Unscored 20,394 (5%)
Highest current score per CVE, by CVSS version. Bars are 0 to 10.
- Score 0: 0
- Score 1: 39
- Score 2: 1,436
- Score 3: 4,134
- Score 4: 19,799
- Score 5: 44,431
- Score 6: 44,926
- Score 7: 69,866
- Score 8: 38,614
- Score 9: 37,339
- Score 10: 1,589
Latest FIRST snapshot. Bars open Browse at that floor.
- ≥ 50% 4,322 (1%)
- 10-50% 12,976 (3%)
- 1-10% 130,105 (34%)
- < 1% 237,131 (62%)
Share of catalog CVEs with scores, CPE, packages, or KEV (a CVE can be in several)
- CVSS scored 383,176 (95%)
- NVD CPE 316,916 (79%)
- MITRE CPE 235,367 (58%)
- GHSA alias 31,882 (8%)
- OSV packages 11,051 (3%)
- CISA KEV 1,739 (<1%)
Most assigned CWEs. KEV overlap in red.
- CWE-79 Cross-site Scripting (XSS) 48,259 32 KEV
- CWE-89 SQL Injection 21,133 31 KEV
- CWE-787 Out-of-bounds Write 15,824 165 KEV
- CWE-119 Buffer Overflow 14,967 68 KEV
- CWE-20 Improper Input Validation 14,661 103 KEV
- CWE-200 Exposure of Sensitive Information 11,925 21 KEV
- CWE-125 Out-of-bounds Read 10,844 19 KEV
- CWE-22 Path Traversal 10,799 99 KEV
- CWE-862 Missing Authorization 10,558 12 KEV
- CWE-352 CSRF 9,815 7 KEV
Vendors with the most tracked CVEs
Products with the most tracked CVEs
Actively exploited vulnerabilities
CVE-2023-22894 KEV
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting…
CVE-2021-3199 KEV
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JW…
CVE-2016-3081 KEV
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled,…
CVE-2015-5477 KEV
bind: TKEY query handling flaw leading to denial of service
CVE-2015-3306 KEV
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and…
Highest exploit probability scores
CVE-2014-0160
openssl: information disclosure in handling of TLS heartbeat extension packets
CVE-2014-3566
SSL/TLS: Padding Oracle On Downgraded Legacy Encryption attack
CVE-2014-6271
bash: specially-crafted environment variables can be used to inject shell commands
CVE-2015-1635
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold a…
CVE-2017-5638
struts2: RCE when performing file upload based on Jakarta Multipart parser