Vulnerability Search
Search by exact CVE, vulnerability wording, recognized software name, or product and version. Examples: Python 3.7, Adobe ColdFusion 2021, remote code execution, or CVE-2025-12345.
Search terms and exact CVE identifiers are sent to the public NVD API. Only public CVE identifiers — never uploaded company or asset data — are used for the other enrichment sources.
Start here
Actively exploited right now, ranked by EVULNABLE Risk. Search above for anything else.
- 97 CVE-2025-55182 Meta — Meta React Server Components Remote Code Execution Vulnerability Immediate
- 97 CVE-2026-35273 Oracle — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability Immediate
- 96 CVE-2025-10035 Fortra — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability Immediate
- 96 CVE-2025-61882 Oracle — Oracle E-Business Suite Unspecified Vulnerability Immediate
- 95 CVE-2025-3248 Langflow — Langflow Missing Authentication Vulnerability Immediate
Searches display the 8 newest NVD results at a time, with a link to the next 8. Recognized product/version searches use NVD CPE applicability data. Patch and workaround status is shown only when a connected source provides supporting guidance.
★ My Watchlist (0)
Saved only in this browser (localStorage) — no account, nothing sent to EVULNABLE. Clearing your browser data clears this too. The Excel and PDF exports are built right here in your browser from those saved items; nothing is sent to EVULNABLE for those either.