U.S. CISA adds Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 1, 20:46 UTC · May 1, 2025Exploit / PoC in the wildCVE-2025-1976CVE-2025-42599CVE-2025-392860
Cyemptive Web Fortress protects web servers against zero-day cyberattacks in real timeHelp Net Security·Feb 18, 00:00 UTC · Feb 18, 2021Exploit / PoC60
New Apache Web Server Bug Threatens Security of Shared Web HostsThe Hacker News·Apr 3, 09:07 UTC · Apr 3, 2019Exploit / PoCCVE-2019-0211CVE-2019-0217CVE-2019-021560
Apache fixes actively exploited web server zeroThe Record·Dec 16, 00:00 UTC · Dec 16, 2022Exploit / PoC in the wildCVE-2021-4177360
Google Researcher Reported 3 Flaws in Apache Web Server SoftwareThe Hacker News·Aug 25, 06:52 UTC · Aug 25, 2020Exploit / PoC in the wildCVE-2020-9490CVE-2020-11984CVE-2020-1199360
Hundreds of ICS products affected by a critical flaw in CODESYS WebVisuSecurity Affairs·Feb 2, 15:00 UTC · Feb 2, 2018Exploit / PoC in the wildCVE-2018-544060
Experts discovered a flaw in GoAhead that affects hundreds of thousands IoT devicesSecurity Affairs·Dec 25, 19:16 UTC · Dec 25, 2017Exploit / PoCCVE-2017-1756260
⚡ Weekly Recap: Zero-Day Exploits, Developer Malware, IoT Botnets, and AIThe Hacker News·Jan 20, 09:20 UTC · Jan 20, 2026Exploit / PoCCVE-2025-29824CVE-2025-2775CVE-2025-2776+19 CVEs60
Medical washer-disinfector appliance's web server open to attackHelp Net Security·Nov 21, 11:33 UTC · Nov 21, 2023Exploit / PoCCVE-2017-724060
Australia Alerts Organizations to Ongoing CMS Exploitation AttacksSecurity Affairs·Jul 13, 07:39 UTC · Jul 13, 2026Exploit / PoC in the wildCVE-2025-34085CVE-2020-36847CVE-2025-12057+15 CVEs60
Critical Flaw in Apache Struts2 Lets Hackers Take Over Web ServersThe Hacker News·Sep 6, 10:53 UTC · Sep 6, 2017Exploit / PoCCVE-2017-980560
79 Netgear router models affected by a dangerous ZeroSecurity Affairs·Jun 18, 16:04 UTC · Jun 18, 2020Exploit / PoC60
NGINX Rift: an 18-year-old flaw in the world's most deployed web server just came to lightSecurity Affairs·May 14, 13:30 UTC · May 14, 2026Exploit / PoC in the wildCVE-2026-42945CVE-2026-42946CVE-2026-40701+1 CVEs60
Apache Warns of Zero-Day Exploit in the Wild — Patch Your Web Servers Now!The Hacker News·Oct 7, 05:31 UTC · Oct 7, 2021Exploit / PoC in the wildCVE-2021-41773CVE-2021-4152460
ZDI offers hefty bounties for zero-days in popular web servers, CMSesHelp Net Security·Jul 25, 00:00 UTC · Jul 25, 2018Exploit / PoC60
Crypto Me0wing attacks: Kitty cashes in on MoneroHelp Net Security·Jun 26, 21:20 UTC · Jun 26, 2018Exploit / PoCCVE-2018-760060
CISA Reports PRC Hackers Using BRICKSTORM for LongThe Hacker News·Dec 5, 09:15 UTC · Dec 5, 2025Exploit / PoCCVE-2023-46805CVE-2024-21887CVE-2024-38812+3 CVEs160
Crooks leverages .htaccess injector on Joomla and WordPress sites for malicious redirectsSecurity Affairs·May 27, 12:39 UTC · May 27, 2019Exploit / PoCCVE-2018-920660
Experts disclosed an unpatched zero-day vulnerability in the firmware of AT&T DirecTV WVB kitSecurity Affairs·Dec 14, 11:32 UTC · Dec 14, 2017Exploit / PoC60
Six-year old bug will likely live forever in Lenovo, Intel productsCyberScoop·Apr 11, 21:36 UTC · Apr 11, 2024Exploit / PoC60
CISA Adds Actively Exploited Broadcom and Commvault Flaws to KEV DatabaseThe Hacker News·May 1, 07:46 UTC · May 1, 2025Exploit / PoC in the wildCVE-2025-1976CVE-2025-392860
NGINX project maintainers fix flaws in LDAP Reference ImplementationSecurity Affairs·Apr 12, 11:25 UTC · Apr 12, 2022Exploit / PoC60
Cisco addresses critical issues in IP Phones and UCS DirectorSecurity Affairs·Apr 17, 17:26 UTC · Apr 17, 2020Exploit / PoCCVE-2020-3161CVE-2020-3239CVE-2020-3240+1 CVEs60
Spring confirms ‘Spring4Shell’ zeroThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoCCVE-2022-22965CVE-2022-2296360
Over 80,000 Hikvision cameras can be easily hackedSecurity Affairs·Aug 23, 16:50 UTC · Aug 23, 2022Exploit / PoC in the wildCVE-2021-3626060
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPsCisco Talos·May 7, 19:50 UTC · May 7, 2021Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs160
All versions of Apache Tomcat are affected by the Ghostcat flawSecurity Affairs·Feb 28, 22:45 UTC · Feb 28, 2020Exploit / PoCCVE-2020-193860
Critical PHPMailer Flaw leaves Millions of Websites Vulnerable to Remote ExploitThe Hacker News·Dec 27, 12:27 UTC · Dec 27, 2016Exploit / PoCCVE-2016-1003360
APT trends report Q1 2021Kaspersky Securelist·Apr 27, 10:00 UTC · Apr 27, 2021Exploit / PoC in the wild60
Dell EMC fixes 3 zero-day vulnerabilities in Data Protection Appliance productsSecurity Affairs·Jan 9, 07:53 UTC · Jan 9, 2018Exploit / PoCCVE-2017-15548CVE-2017-15549CVE-2017-1555060
Thousands of applications affected by a zeroSecurity Affairs·Oct 20, 08:38 UTC · Oct 20, 2018Exploit / PoC in the wildCVE-2018-920660
Cisco IOS XE zero-day exploited by attackers to deliver implant (CVE-2023-20198)Help Net Security·Oct 31, 10:28 UTC · Oct 31, 2023Exploit / PoCCVE-2023-20198CVE-2021-143560
Hackers found leveraging three SonicWall zero-day vulnerabilitiesHelp Net Security·Apr 21, 00:00 UTC · Apr 21, 2021Exploit / PoCCVE-2021-20021CVE-2021-20022CVE-2021-2002360
Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely CompromisedThe Hacker News·Apr 29, 10:40 UTC · Apr 29, 2025Exploit / PoC in the wildCVE-2024-58136CVE-2024-4990CVE-2025-32432+1 CVEs60
FBI removes web shells from hacked Microsoft Exchange serversHelp Net Security·Apr 14, 00:00 UTC · Apr 14, 2021Exploit / PoC160
Atlassian warns that Confluence zeroThe Record·Jan 13, 00:00 UTC · Jan 13, 2023Exploit / PoC in the wildCVE-2022-2613460
Threat Advisory: Apache HTTP Server zero-day vulnerability opens door for attackersCisco Talos·Oct 7, 19:36 UTC · Oct 7, 2021Exploit / PoC in the wildCVE-2021-41733CVE-2021-4201360
0-Day Flaws in Vanilla Forums Let Remote Attackers Hack WebsitesThe Hacker News·May 12, 18:09 UTC · May 12, 2017Exploit / PoCCVE-2016-10033CVE-2016-1007360
CISA Reveals Federal Agency Was Compromised Via GeoServer ExploitInfosecurity Magazine·Sep 24, 10:30 UTC · Sep 24, 2025Exploit / PoC in the wild60
Researchers Identify Multiple China Hacker Groups Exploiting Ivanti Security FlawsThe Hacker News·Apr 6, 09:12 UTC · Apr 6, 2024Exploit / PoCCVE-2023-46805CVE-2024-21887CVE-2024-2189360