Situational awareness for NIS2 and KRITIS

German vulnerability intelligence in real time.

We aggregate NVD, CISA KEV, BSI CERT-Bund, GHSA and 40+ OSV ecosystems, enrich with German analysis, NIS2 and CRA (Cyber Resilience Act) mapping, and sector context — delivered as API, webhook, MISP feed and RSS.

Vulnerability explorer

970,271 advisories curated for SMB and KRITIS operators under NIS2. Actively exploited vulnerabilities (CISA KEV) and critical CVEs are surfaced first.

Situational stats

Refreshed every 30 seconds — counters tick live without a reload.

CVE inflation, but CISA is getting faster

The volume of published CVEs is growing exponentially — yet the share of actually exploited vulnerabilities stays in the low single digits. In parallel, CISA has cut the time between CVE publication and KEV listing down to a handful of days. Together: less noise, sharper signal.

Severity mix per yearCriticalHighMedium / LowUnscoredof which KEVof which ransomware
25%50%75%100%10K20145.4K20158.4K201616K201715K201817K201918K202030K202152K202243K2023114K2024310K2025266K2026343597401%n
Time-to-KEV (median, days)

Median days between CVE publication and CISA-KEV listing. Lower = prioritized sooner.

14720211,9032022122023212024252025142026

Year-to-date CVE publications

Cumulative CVE publications per year, derived from the earliest publication date across our ingested sources (NVD, CVE.org, OSV, MSRC, Debian, Ubuntu). Note: our capture ratio against the MITRE CVE List is currently below 100% — NVD records with status "Received / Awaiting Analysis" are now counted (since 2026-06-07), a full cvelistV5 sync follows in a later wave. A 1 : 1 match with FIRST/first.org/epss/data_stats is the target but not yet reached.

13k25k38k50kJanFebMarAprMayJunJulAugSepOctNovDec2017201820192020202120222023202420252026Year-to-Date CVEs35,085Average per day: 167.9YoY change: +199.9% (23,386)

Threat Intelligence

Check live indicators in seconds

Look up an IP, domain, URL or file hash against our consolidated IoC database. Fed by abuse.ch (URLhaus, MalwareBazaar, Feodo Tracker), AlienVault OTX, CISA and curated industry feeds.

Threat-intel catalog

indicators total

525,501

across all sources, deduplicated

new in 24 h

71,287

freshness as a situational signal

active feeds

11

abuse.ch, OTX, internal

Top sources

  • blocklist_de173,060
  • cins_army156,647
  • abusech_threatfox116,859
  • ipsum66,392
  • abusech_urlhaus46,674
  • abusech_malware_bazaar16,802

Quick lookup

One IP, domain, URL or file hash — we return score and last-seen. Full provenance is available to signed-in users.

Most recently observed indicators

redacted preview

  • 🇯🇵27.133.x.xScore 92
    ipJPAS9370SAKURA-B SAKURA Internet Inc.Cobalt Strikeabusech_feodo_trackerabusech_threatfox2026-07-28 12:06 UTC
  • 🇬🇧178.62.x.xScore 92
    ipGBAS14061DIGITALOCEAN-ASN - DigitalOcean, LLCCobalt Strikeabusech_feodo_trackerabusech_threatfox2026-07-28 12:06 UTC
  • 🇺🇸34.204.x.xScore 90
    ipUSAS14618AMAZON-AESQakBotabusech_feodo_tracker2026-07-28 12:06 UTC
  • 🇺🇸50.16.x.xScore 90
    ipUSAS14618AMAZON-AESQakBotabusech_feodo_tracker2026-07-28 12:06 UTC
  • 🇺🇸162.243.x.xScore 92
    ipUSAS14061DIGITALOCEAN-ASNbotnet_ccabusech_feodo_trackerabusech_threatfox2026-07-28 12:06 UTC
  • http://*.29.57:60054/…Score 85
    urlMoziabusech_urlhaus2026-07-28 12:06 UTC
  • http://*.194.171:48855/…Score 85
    urlmipsabusech_urlhaus2026-07-28 12:06 UTC
  • http://*.82.226:49051/…Score 85
    urlMoziabusech_urlhaus2026-07-28 12:06 UTC

Note: IP and domain values are redacted in the public view for DSGVO reasons (1.2.x.x, *.example.com). Full values are available to customers via the API.

Situational news & topics

Current cyber situation from curated feeds

Aggregated from BSI Bürger-CERT, BSI WID, SANS NewsBites, Krebs on Security, The Hacker News and the Allianz für Cyber-Sicherheit. Partner ads are filtered out.

All news

Editorial

From the blog

Blog

Latest priority advisories

Ranked by priority score — KEV, EPSS, CVSS, recency and CPE relevance.

  • CVE-2026-10520

    [KEV] [critical] Ivanti Sentry — Ivanti Sentry OS Command Injection Vulnerability

    An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

    Actively exploitedCritical2026-06-09 16:16 UTC
  • CVE-2026-48907

    [KEV] [critical] Widget Factory Joomla Content Editor: Schwachstelle ermöglicht Codeausführung

    A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

    Actively exploitedCritical2026-06-18 10:19 UTC
  • CVE-2026-34908

    [KEV] [critical] Ubiquiti UniFi OS Server: Mehrere Schwachstellen

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.

    Actively exploitedCritical2026-06-24 08:31 UTC
  • CVE-2026-32202

    [KEV] [medium] Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff

    Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

    Actively exploited2026-07-17 07:32 UTC
  • CVE-2021-22555

    [KEV] [high] Oracle JD Edwards: Mehrere Schwachstellen

    A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

    Actively exploited2026-07-22 09:52 UTC
  • CVE-2023-22518

    [KEV] [high] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye und Jira): Mehrere Schwachstellen

    All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.  Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

    Actively exploited2026-07-20 10:42 UTC