← Back to feed 2026-08-04
9,166
Total vulnerabilities (30 days)
512
Critical severity
5
Actively exploited (CISA KEV)
1130
High EPSS (>50th %ile)

By severity

CRITICAL
512
HIGH
3,270
MEDIUM
2,948
LOW
198
UNKNOWN
2,238

By source

Microsoft
6,969
NVD
1,952
GitHub
69
Fortinet
48
OSS-Security
47
OpenStack
30
OSV
21
Ubuntu
9
Arista
8
Debian
8
CISA-KEV
2
Red Hat
2
Featured
1

CVSS score distribution

0.0–0.5
0
0.5–1.0
1
1.0–1.5
1
1.5–2.0
8
2.0–2.5
33
2.5–3.0
21
3.0–3.5
67
3.5–4.0
64
4.0–4.5
289
4.5–5.0
185
5.0–5.5
286
5.5–6.0
1,345
6.0–6.5
276
6.5–7.0
556
7.0–7.5
905
7.5–8.0
1,504
8.0–8.5
337
8.5–9.0
515
9.0–9.5
178
9.5–10.0
331

Daily severity heatmap

Low
Critical  
No data

Top affected products / packages

ProductCVEsMax CVSSWorst severity
Windows98149.9CRITICAL
azl3544910.0CRITICAL
Microsoft419510.0CRITICAL
cbl2207810.0CRITICAL
google/chrome3419.6CRITICAL
.NET1598.8HIGH
Azure14310.0CRITICAL
Office678.2HIGH
cm1649.8CRITICAL
CBL489.8CRITICAL
google/android469.6CRITICAL
apache/traffic_server359.2CRITICAL
apple/iphone_os339.6CRITICAL
apple/macos209.6CRITICAL
Visual199.6CRITICAL
microsoft/windows149.6CRITICAL
gitlab/gitlab138.5HIGH
3D137.8HIGH
cm2129.8CRITICAL
Remote118.8HIGH
Ironic:9UNKNOWN
Nuance89.8CRITICAL
asustor/data_master88.7HIGH
adobe/bridge88.6HIGH
PowerShell87.8HIGH
ibm/websphere_application_server69.4CRITICAL
npm/flowise6CRITICAL
Dynamics59.3CRITICAL
ibm/sterling_b2b_integrator58.1HIGH
ibm/sterling_file_gateway58.1HIGH

Highest EPSS scores (top 20)

CVE IDTitleEPSS %ileCVSSSeverity
CVE-2025-53770Microsoft SharePoint Server Remote Code Execution Vulnerability100.0%9.8CRITICAL
CVE-2025-49704Microsoft SharePoint Remote Code Execution Vulnerability100.0%8.8HIGH
CVE-2025-53771Microsoft SharePoint Server Spoofing Vulnerability100.0%6.5MEDIUM
CVE-2025-49706Microsoft SharePoint Server Spoofing Vulnerability100.0%6.5MEDIUM
CVE-2026-43284xfrm: esp: avoid in-place decrypt on shared skb frags99.8%7.8HIGH
CVE-2026-43500rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present99.8%7.8HIGH
CVE-2023-21547Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability99.8%7.5HIGH
CVE-2023-21758Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability99.8%7.5HIGH
CVE-2024-27316Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation fram99.8%7.5HIGH
CVE-2023-45288HTTP/2 CONTINUATION flood in net/http99.8%7.5HIGH
CVE-2024-2961The iconv() function in the GNU C Library versions 2.39 and older may overflow t99.8%7.3HIGH
CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place99.8%5.5MEDIUM
CVE-2024-27983An attacker can make the Node.js HTTP/2 server completely unavailable by sending99.7%8.2HIGH
CVE-2024-26256Libarchive Remote Code Execution Vulnerability99.7%7.8HIGH
CVE-2024-30044Microsoft SharePoint Server Remote Code Execution Vulnerability99.7%7.2HIGH
CVE-2024-28182Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU us99.7%5.3MEDIUM
CVE-2025-49844Security Advisory 013999.7%UNKNOWN
CVE-2026-41089Windows Netlogon Remote Code Execution Vulnerability99.6%9.8CRITICAL
CVE-2023-50868MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU99.6%7.5HIGH
CVE-2026-50522Microsoft SharePoint Remote Code Execution Vulnerability99.5%9.8CRITICAL