Investigate
Search by exact CVE, vulnerability wording, recognized software name, or product and version. Examples: Python 3.7, Adobe ColdFusion 2021, remote code execution, or CVE-2025-12345.
Search terms and exact CVE identifiers are sent to the public NVD API. Only public CVE identifiers — never uploaded company or asset data — are used for the other enrichment sources.
Start here
Actively exploited right now, ranked by EVULNABLE Risk. Search above for anything else.
- 97 CVE-2025-55182 Meta — Meta React Server Components Remote Code Execution Vulnerability
- 97 CVE-2026-35273 Oracle — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
- 96 CVE-2025-10035 Fortra — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
- 96 CVE-2025-61882 Oracle — Oracle E-Business Suite Unspecified Vulnerability
- 95 CVE-2025-3248 Langflow — Langflow Missing Authentication Vulnerability
★ My Watchlist (0)
Saved only in this browser (localStorage) — no account, nothing sent to EVULNABLE. Clearing your browser data clears this too. The Excel and PDF exports are built right here in your browser from those saved items; nothing is sent to EVULNABLE for those either.
