Get early warning on zero-day vulnerabilities being actively exploited. Our 20-year dataset surfaces patterns that predict zero-day risk in your environment.
API Coverage
Developer-first
Single REST API key. JSON everywhere. Start for free with 30 req/min.
Get your free key →Latest Intelligence
Two critical zero-day vulnerabilities in Ivanti Connect Secure are being chained to achieve pre-authentication remote code execution, with CISA issuing emergency directives.
CVE-2021-44228 (Log4Shell), a CVSS 10.0 remote code execution flaw in Apache Log4j discovered December 9, 2021, achieved rapid widespread exploitation across 48%+ of corporate networks globally, spawning follow-up vulnerabilities CVE-2021-45046 and CVE-2021-45105, with continued exploitation by state-sponsored and criminal actors through 2022.
Google Threat Intelligence tracked 90 zero-day vulnerabilities actively exploited in 2025, with enterprise technologies accounting for 48% of attacks. State-sponsored groups continue targeting edge devices and security appliances as primary network entry points.
Explore other topics