Pwn2Own Automotive 2025 Day 2: organizers awarded $335,500Security Affairs·Jan 23, 20:48 UTC · Jan 23, 2025Exploit / PoC60
Pwn2Own Automotive 2025 Day 1: organizers awarded $382,750 for 16 zeroSecurity Affairs·Jan 22, 22:01 UTC · Jan 22, 2025Exploit / PoC60
WordPress Hunk Companion Plugin Flaw Exploited to Silently Install Vulnerable PluginsThe Hacker News·Dec 12, 10:02 UTC · Dec 12, 2024Exploit / PoCCVE-2024-11972CVE-2024-50498CVE-2024-1120560
Critical Flaw in ProjectSend Under Active Exploitation Against PublicThe Hacker News·Dec 5, 04:45 UTC · Dec 5, 2024Exploit / PoC in the wildCVE-2024-1168060
Pwn2Own Ireland 2024 Day 2: participants demonstrated an exploit against Samsung Galaxy S24Security Affairs·Oct 24, 20:53 UTC · Oct 24, 2024Exploit / PoC60
Critical LiteSpeed Cache Plugin Flaw Exposes WordPress SitesInfosecurity Magazine·Aug 21, 16:30 UTC · Aug 21, 2024Exploit / PoC60
GitHub Token Leak Exposes Python's Core Repositories to Potential AttacksThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2024Exploit / PoC in the wild160
Network Attack Trends: FebruaryPalo Alto Unit 42·Jun 6, 12:33 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2021-25296CVE-2021-25297CVE-2021-25298+4 CVEs60
Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious PurposesPalo Alto Unit 42·Jun 6, 01:14 UTC · Jun 6, 2024Exploit / PoCCVE-2017-9506CVE-2017-12629CVE-2019-2767+23 CVEs60
Network Security Trends: AugustPalo Alto Unit 42·Jun 6, 00:57 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2021-40438CVE-2021-34473CVE-2021-38647+9 CVEs60
CISA adds ownCloud and Google Chrome bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 1, 11:04 UTC · Dec 1, 2023Exploit / PoC in the wildCVE-2023-6345CVE-2023-49103CVE-2023-521760
CISA adds Sophos Web Appliance bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 22, 09:48 UTC · Nov 22, 2023Exploit / PoC in the wildCVE-2023-36584CVE-2023-1671CVE-2023-255160
Citrix NetScaler ADC and Gateway Devices Under Attack: CISA Urges Immediate ActionThe Hacker News·Sep 7, 03:22 UTC · Sep 7, 2023Exploit / PoC in the wildCVE-2023-351960
CISA Adds Citrix ShareFile Flaw to KEV Catalog Due to In-theThe Hacker News·Aug 21, 03:43 UTC · Aug 21, 2023Exploit / PoC in the wildCVE-2023-24489CVE-2023-351960
Citrix NetScaler zero-day exploited in the wild, patch is available (CVE-2023-3519)Help Net Security·Jul 21, 11:15 UTC · Jul 21, 2023Exploit / PoC in the wildCVE-2023-3519CVE-2023-3466CVE-2023-3467+2 CVEs60
Urgent WordPress Update Fixes Critical Flaw in Jetpack Plugin on Million of SitesThe Hacker News·Jun 1, 04:02 UTC · Jun 1, 2023Exploit / PoC in the wildCVE-2023-2878260
Critical flaw in WooCommerce Payments plugin allows site takeoverSecurity Affairs·Mar 24, 14:45 UTC · Mar 24, 2023Exploit / PoC in the wild60
CISA adds 3 new bugs to Known Exploited Vulnerabilities CatalogSecurity Affairs·Mar 8, 11:58 UTC · Mar 8, 2023Exploit / PoC in the wildCVE-2022-35914CVE-2022-33891CVE-2022-28810+1 CVEs60
Surge in Magento 2 template attacks exploiting CVE-2022Security Affairs·Sep 23, 13:55 UTC · Sep 23, 2022Exploit / PoC in the wildCVE-2022-2408660
Zero Day attacks target online stores using PrestaShopSecurity Affairs·Jul 26, 06:23 UTC · Jul 26, 2022Exploit / PoCCVE-2022-3640860
DirtyMoe modules expand the bot using wormSecurity Affairs·Mar 21, 08:03 UTC · Mar 21, 2022Exploit / PoCCVE-2020-0674CVE-2019-9082CVE-2019-2725+3 CVEs60
Critical Magento zero-day flaw CVE-2022Security Affairs·Feb 14, 12:09 UTC · Feb 14, 2022Exploit / PoC in the wildCVE-2022-2408660
New Nagios Software Bugs Could Let Hackers Take Over IT InfrastructuresThe Hacker News·Sep 27, 04:39 UTC · Sep 27, 2021Exploit / PoCCVE-2021-37344CVE-2021-37346CVE-2021-37350+8 CVEs160
Hackers exploit 3-years old flaw to wipe Western Digital devicesSecurity Affairs·Jun 25, 18:07 UTC · Jun 25, 2021Exploit / PoC in the wildCVE-2018-1847260
Hackers Actively Exploiting 0-Day in WordPress Plugin Installed on Over 17,000 SitesThe Hacker News·Jun 3, 05:51 UTC · Jun 3, 2021Exploit / PoC in the wild60
Critical Zero-Day in WordPress Plugin Under Active AttackInfosecurity Magazine·Jun 2, 11:06 UTC · Jun 2, 2021Exploit / PoC in the wild60
Researcher discloses exploit code for a vBulletin zeroSecurity Affairs·Aug 11, 08:14 UTC · Aug 11, 2020Exploit / PoCCVE-2019-1675960
Research shows that devices banned by US government lack basic security practicesHelp Net Security·Jul 28, 10:13 UTC · Jul 28, 2020Exploit / PoC60
vBulletin zero-day exploited in the wild in wake of exploit releaseHelp Net Security·May 28, 11:23 UTC · May 28, 2020Exploit / PoC in the wildCVE-2019-1675960
Cryptocurrency miners aren’t dead yet: Documenting the voracious but simple “Panda”Cisco Talos·Sep 17, 15:09 UTC · Sep 17, 2019Exploit / PoCCVE-2017-10271CVE-2017-563860
Crooks leverages .htaccess injector on Joomla and WordPress sites for malicious redirectsSecurity Affairs·May 27, 12:39 UTC · May 27, 2019Exploit / PoCCVE-2018-920660
Experts release PoC exploit for flaw in WordPress WooCommerceSecurity Affairs·Apr 27, 11:02 UTC · Apr 27, 2019Exploit / PoC60
Hackers Actively Exploiting WidelyThe Hacker News·Apr 23, 19:23 UTC · Apr 23, 2019Exploit / PoC in the wildCVE-2019-997860
New Apache Web Server Bug Threatens Security of Shared Web HostsThe Hacker News·Apr 3, 09:07 UTC · Apr 3, 2019Exploit / PoCCVE-2019-0211CVE-2019-0217CVE-2019-021560
A critical flaw in WordPress GDPR compliance plugin exploited in the wildSecurity Affairs·Nov 12, 10:08 UTC · Nov 12, 2018Exploit / PoC in the wild60
CVE-2018-15961: Adobe ColdFusion Flaw exploited in attacks in the wildSecurity Affairs·Nov 11, 13:58 UTC · Nov 11, 2018Exploit / PoC in the wildCVE-2018-1596160
Python-based attack tools are the most common vector for launching exploit attemptsHelp Net Security·Oct 1, 00:00 UTC · Oct 1, 2018Exploit / PoC157