Which vulnerabilities attackers can exploit — and which they already are. Aggregated from public exploit repositories, honeypot telemetry, advisories, and security reporting.
Exploitation concentrates at the top: most in-the-wild activity targets critical and high-severity CVEs.
Of the 3,742 vulnerabilities with in-the-wild exploitation evidence, 2,078 are not in the CISA KEV catalog.
Vulnerabilities whose first exploitation evidence appeared in the window (cumulative).
263,409 exploitation records across 3,743 vulnerabilities. Ranked by unique CVEs with evidence from each source — honeypot telemetry reports the same hot CVEs repeatedly, so record volume alone would overstate it.
87,057 tracked exploits, 42,944 linked to a specific CVE.
Exploit availability comes from public exploit repositories and proof-of-concept tracking; in-the-wild evidence combines honeypot and sensor telemetry, CISA KEV, vendor advisories, and security reporting. Counts refresh continuously as Mallory ingests new sources.