VULNERABILITY REFERENCE & TRIAGE · CVSS · EPSS · CISA KEV · PUBLIC PoC

Most CVEs don't matter.
Know the ones that do.

Every published CVE since 1999, ranked by real-world exploitation — with public exploit code and copy-paste tests where they exist.

345,000+CVEs indexed — all years
13,040Last 45 days
23Known exploited
2,542With public PoC
2026-07-22Updated
Severity mix

Explore

13,040 CVEs
CVE ID Severity EPSS Product / summary Signals Published

Showing CVEs from the last 45 days. Testing a specific product (e.g. a years-old MikroTik or router flaw)? Turn on All years to search every published CVE, 1999–present.All-years mode: searching the full CVE corpus (all history, via the live database). The ● PoC signal marks entries with public exploit / proof-of-concept code; add the Has public PoC filter to see only those. Each result links to its detail page, poc.json, and test commands.

Browse by vendor

What is a CVE?

A CVE (Common Vulnerabilities and Exposures) is a public identifier for a specific software or hardware flaw. Each gets a unique ID like CVE-2024-3094, a description, and — once analyzed — a CVSS severity score and a list of affected products.

Reading a CVSS score

  • Critical 9.0+ trivially exploitable, severe impact
  • High 7.0–8.9 serious, often remotely exploitable
  • Medium 4.0–6.9 meaningful but conditional
  • Low 0.1–3.9 limited impact or hard to reach

A vulnerability reference built for triage & testing

Vulnpedia indexes public CVE data and fuses it into an operator's view: what's actively exploited (CISA KEV), what's statistically likely to be (EPSS), what public exploit or proof-of-concept code exists, and what an attacker needs to pull it off. Every CVE with public PoC code also exposes a machine-readable poc.json endpoint so you — or an automation agent — can find and test it against your own equipment. Rebuilt daily from CVE.org, NVD, CISA, FIRST, ExploitDB, and Nuclei.