First-party CVE register
Observed CVE activity
A delayed public record of exploit-like activity mapped to known vulnerabilities. Confidence describes the CVE association—not whether exploitation succeeded.
Understand detection labels: open the glossary ↓
First and last observed dates refer to deduplicated exploit-like activity potentially consistent with the CVE. They do not establish successful execution. Only findings older than 24 hours and supported by at least 4 distinct sources are shown. Public dates are rounded to the day and internal volumes are withheld.
Confidence guide
- High
- A specific deterministic match strongly identifies the CVE.
- Medium
- Several distinctive indicators support the mapping, with ambiguity remaining.
- Working hypothesis
- The activity is exploit-associated and plausibly linked, but not specific enough for a firmer claim.
- Low
- Weak probing or partial similarity retained as a lead.
Evidence ledger
Potentially consistent exploit attempts
| Assessment | Vulnerability | First observed | Last observed | Detection basis | Public context | Open dossier |
|---|---|---|---|---|---|---|
| Medium confidenceMapping score 70/100 | CVE-2025-49002dataease · dataease | Potentially consistent attempt | last 7 days | Disclosure quorum met · assessed 24 Sept 2026 | unknownExploit availability: none known | |
| High confidenceMapping score 95/100 | CVE-2024-4577php · php | Potentially consistent attempt | last 7 days | Disclosure quorum met · assessed 24 Sept 2026 | kevExploit availability: poc | |
| High confidenceMapping score 95/100 | CVE-2023-46805ivanti · connect secure | Potentially consistent attempt | last 7 days | Disclosure quorum met · assessed 25 Sept 2026 | kevExploit availability: none known | |
| High confidenceMapping score 95/100 | CVE-2017-9841oracle · communications diameter signaling router | Potentially consistent attempt | last 7 days | Disclosure quorum met · assessed 24 Sept 2026 | kevExploit availability: none known | |
| Medium confidenceMapping score 80/100 | CVE-2020-7136hpe · smart update manager | Potentially consistent attempt | last 7 days | Disclosure quorum met · assessed 23 Sept 2026 | unknownExploit availability: none known | |
| High confidenceMapping score 100/100 | CVE-2018-13382fortinet · fortiproxy | Potentially consistent attempt | last 7 days | Disclosure quorum met · assessed 23 Sept 2026 | kevExploit availability: none known | |
| High confidenceMapping score 95/100 | CVE-2021-41773apache · http server | Potentially consistent attempt | last 30 days | Disclosure quorum met · assessed 18 Sept 2026 | kevExploit availability: none known | |
| Low confidenceMapping score 35/100 | CVE-2018-13379fortinet · fortiproxy | Potentially consistent attempt | last 30 days | Disclosure quorum met · assessed 17 Sept 2026 | kevExploit availability: technical details | |
| Low confidenceMapping score 35/100 | CVE-2021-34473microsoft · exchange server | Potentially consistent attempt | last 30 days | Disclosure quorum met · assessed 17 Sept 2026 | kevExploit availability: none known | |
| High confidenceMapping score 95/100 | CVE-2021-42013apache · http server | Potentially consistent attempt | last 30 days | Disclosure quorum met · assessed 13 Sept 2026 | kevExploit availability: none known | |
| High confidenceMapping score 95/100 | CVE-2025-30208vitejs · vite | Potentially consistent attempt | last 30 days | Disclosure quorum met · assessed 13 Sept 2026 | unknownExploit availability: none known | |
| High confidenceMapping score 100/100 | CVE-2025-57808esphome · esphome firmware | Potentially consistent attempt | last 30 days | Disclosure quorum met · assessed 19 Sept 2026 | unknownExploit availability: none known | |
| High confidenceMapping score 95/100 | CVE-2019-11510ivanti · connect secure | Potentially consistent attempt | last 30 days | Disclosure quorum met · assessed 13 Sept 2026 | kevExploit availability: none known | |
| Medium confidenceMapping score 70/100 | CVE-2018-3810oturia · smart google code inserter | Potentially consistent attempt | last 30 days | Disclosure quorum met · assessed 19 Sept 2026 | unknownExploit availability: none known | |
| Low confidenceMapping score 35/100 | CVE-2021-26855microsoft · exchange server | Potentially consistent attempt | last 30 days | Disclosure quorum met · assessed 31 Aug 2026 | kevExploit availability: technical details | |
| Medium confidenceMapping score 70/100 | CVE-2024-51483Product metadata unresolved | Potentially consistent attempt | older | Disclosure quorum met · assessed 19 Sept 2026 | unknownExploit availability: none known |
Understanding your detections
Use these labels to understand where a finding comes from and how strongly it points to an exploitation attempt. Open the CVE record to review the supporting evidence.
Where does the detection come from?
- VTP curated A detection rule maintained by VTP
The finding uses a rule maintained by VTP. Rules may draw on technical reports, exploit examples or templates. Rules imported directly from Nuclei, Metasploit or Exploit-DB may appear under those source names instead.
What this tells you: who maintains the rule. Review its references to see the evidence behind it. On a rule listing, this label alone does not mean an attack has been observed.
- First party sensor Activity reported by a connected honeypot
A honeypot connected to VTP reported activity it associates with this CVE. This gives you a direct sensor observation, rather than a report from an external publication.
What this tells you: where the signal was observed. The link to the CVE may still need confirmation; check the confidence rating and the matching evidence in the record.
What does the detected activity mean?
- Exploit trigger A pattern used to identify exploitation attempts
The rule looks for a request designed to trigger a vulnerability. A sufficiently specific match in honeypot traffic supports an exploitation attempt consistent with that CVE.
Example: a request sends a characteristic malicious parameter to the endpoint affected by the vulnerability.
On a rule listing, this describes what the rule detects. On a finding, review the confidence rating to understand how firmly the observed request is linked to the CVE.
- Exploitation associated A related signal that needs confirmation
The activity may be relevant to exploitation, but it does not provide enough evidence to identify an exploitation attempt against this CVE.
Example: a request checks a product version, or a response reveals a detail associated with the vulnerability, without showing that an exploit was sent.
How to use it: treat it as a lead to investigate. Review what was observed and what evidence is still missing before treating it as a CVE exploitation attempt.
An exploitation attempt is not the same as a successful compromise. These labels help you interpret honeypot activity and detection methods. They do not establish that your production systems were attacked or compromised.