VULNERABILITY REFERENCE & TRIAGE · CVSS · EPSS · CISA KEV · PUBLIC PoC
Most CVEs don't matter.
Know the ones that do.
Every published CVE since 1999, ranked by real-world exploitation — with public exploit code and copy-paste tests where they exist.
Explore
13,040 CVEsShowing CVEs from the last 45 days. Testing a specific product (e.g. a years-old MikroTik or router flaw)? Turn on All years to search every published CVE, 1999–present.All-years mode: searching the full CVE corpus (all history, via the live database). The ● PoC signal marks entries with public exploit / proof-of-concept code; add the Has public PoC filter to see only those. Each result links to its detail page, poc.json, and test commands.
Browse by vendor
What is a CVE?
A CVE (Common Vulnerabilities and Exposures) is a public identifier for a specific software or hardware flaw. Each gets a unique ID like CVE-2024-3094, a description, and — once analyzed — a CVSS severity score and a list of affected products.
Reading a CVSS score
- Critical 9.0+ trivially exploitable, severe impact
- High 7.0–8.9 serious, often remotely exploitable
- Medium 4.0–6.9 meaningful but conditional
- Low 0.1–3.9 limited impact or hard to reach
A vulnerability reference built for triage & testing
Vulnpedia indexes public CVE data and fuses it into an operator's view: what's actively exploited (CISA KEV), what's statistically likely to be (EPSS), what public exploit or proof-of-concept code exists, and what an attacker needs to pull it off. Every CVE with public PoC code also exposes a machine-readable poc.json endpoint so you — or an automation agent — can find and test it against your own equipment. Rebuilt daily from CVE.org, NVD, CISA, FIRST, ExploitDB, and Nuclei.