Which vulnerabilities attackers can exploit — and which they already are. Aggregated from public exploit repositories, honeypot telemetry, advisories, and security reporting.
Vulnerabilities whose in-the-wild exploitation evidence began in the last 24 hours — new attacks and fresh activity against long-known CVEs alike.
Exploitation concentrates at the top: most in-the-wild activity targets critical and high-severity CVEs.
Of the 3,867 vulnerabilities with in-the-wild exploitation evidence, 2,157 are not in the CISA KEV catalog.
Vulnerabilities whose first exploitation evidence appeared in the window (cumulative).
265,900 exploitation records across 3,868 vulnerabilities. Ranked by unique CVEs with evidence from each source — honeypot telemetry reports the same hot CVEs repeatedly, so record volume alone would overstate it.
88,207 tracked exploits, 47,171 linked to a specific CVE.
Exploit availability comes from public exploit repositories and proof-of-concept tracking; in-the-wild evidence combines honeypot and sensor telemetry, CISA KEV, vendor advisories, and security reporting. Counts refresh continuously as Mallory ingests new sources.