Anthropic: Mythos finds more than 10,000 software flaws in first monthCyberScoop·May 26, 15:15 UTC · May 26, 2026Exploit / PoC in the wild60
Linux Kernel bug Fragnesia allows local root access attacksSecurity Affairs·May 17, 12:40 UTC · May 17, 2026Exploit / PoCCVE-2026-4630050
Pwn2Own Berlin 2026, Day One: $523,000 paid out, AI products fallSecurity Affairs·May 15, 05:20 UTC · May 15, 2026Exploit / PoC60
PackageGate bugs let attackers bypass protections in NPM, PNPM, VLT, and BunSecurity Affairs·Jan 28, 08:43 UTC · Jan 28, 2026Exploit / PoC160
Actively Exploited WSUS Bug Added to CISA KEV ListInfosecurity Magazine·Oct 28, 09:45 UTC · Oct 28, 2025Exploit / PoC in the wildCVE-2025-5928760
New SAP NetWeaver Bug Lets Attackers Take Over Servers Without LoginThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Exploit / PoC in the wildCVE-2025-42944CVE-2025-42937CVE-2025-4291060
Apple Bug Bounty Payouts Can Now Top $5mInfosecurity Magazine·Oct 13, 10:30 UTC · Oct 13, 2025Exploit / PoC60
Week in review: MITRE ATT&CK v17.0 released, PoC for Erlang/OTP SSH bug is publicHelp Net Security·Apr 27, 00:00 UTC · Apr 27, 2025Exploit / PoCCVE-2025-32433CVE-2025-34028CVE-2025-2761060
‘Severe’ bug in ChatGPT’s API could be used to DDoS websitesCyberScoop·Jan 22, 19:45 UTC · Jan 22, 2025Exploit / PoC in the wild160
Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler BugsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-21410+6 CVEs60
Mozilla fixes critical Firefox bug exploited in the wildThe Record·Oct 10, 18:31 UTC · Oct 10, 2024Exploit / PoC in the wildCVE-2024-968060
U.S. CISA adds Windows and Qualcomm bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 10, 11:10 UTC · Oct 10, 2024Exploit / PoC in the wildCVE-2024-43047CVE-2024-43572CVE-2024-4357360
Zimbra bug causes alarm among researchers, CERTs after exploitation attemptsThe Record·Oct 2, 18:09 UTC · Oct 2, 2024Exploit / PoC in the wildCVE-2024-4551960
Almost unfixable “Sinkclose” bug affects hundreds of millions of AMD chipsArs Technica · Security·Aug 10, 13:00 UTC · Aug 10, 2024Exploit / PoC60
Palo Alto Networks warns of zeroThe Record·Apr 12, 14:52 UTC · Apr 12, 2024Exploit / PoC in the wildCVE-2024-340060
Chinese government hacker exploiting ScreenConnect, F5 bugs to attack defense and government entitiesThe Record·Mar 21, 20:48 UTC · Mar 21, 2024Exploit / PoCCVE-2024-1709CVE-2023-4674760
CISA warns of Fortinet bug likely being exploited in the wildThe Record·Feb 12, 16:29 UTC · Feb 12, 2024Exploit / PoC in the wildCVE-2024-21762CVE-2024-23313CVE-2024-2311360
CISA adds Google Chromium V8 Type Confusion bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 7, 19:30 UTC · Feb 7, 2024Exploit / PoC in the wildCVE-2023-4762CVE-2023-41993CVE-2023-41991+1 CVEs60
CISA adds Apple improper authentication bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 5, 18:39 UTC · Feb 5, 2024Exploit / PoC in the wildCVE-2022-4861860
CISA adds VMware vCenter Server bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 23, 08:00 UTC · Jan 23, 2024Exploit / PoC in the wildCVE-2023-34048CVE-2023-20867160
CISA says latest VMware analytics bug being exploitedThe Record·Jun 23, 12:17 UTC · Jun 23, 2023Exploit / PoC in the wildCVE-2023-20887CVE-2016-9079CVE-2016-016560
KeePass fixed bug that allows extraction of cleartext master pwdSecurity Affairs·Jun 5, 18:24 UTC · Jun 5, 2023Exploit / PoCCVE-2023-3278450
Microsoft fixed Azure AD bug that led to Bing.com results manipulation and account takeoverSecurity Affairs·Apr 3, 11:32 UTC · Apr 3, 2023Exploit / PoC in the wild160
First Fully Weaponized Spectre Exploit Discovered OnlineThe Record·Jan 30, 00:00 UTC · Jan 30, 2023Exploit / PoC in the wild60
Experts downplay reach of Apache bug ‘Text4Shell’The Record·Jan 9, 00:00 UTC · Jan 9, 2023Exploit / PoCCVE-2022-4288960
PoC published for new Microsoft PatchGuard (KPP) bypassThe Record·Dec 10, 00:00 UTC · Dec 10, 2022Exploit / PoC45
Microsoft Finds Account Takeover Bug in TikTokInfosecurity Magazine·Sep 1, 09:50 UTC · Sep 1, 2022Exploit / PoC in the wildCVE-2022-2879960
CISA adds Sophos firewall bug to Known Exploited Vulnerabilities CatalogSecurity Affairs·Apr 1, 08:29 UTC · Apr 1, 2022Exploit / PoC in the wildCVE-2022-1040CVE-2022-26871CVE-2021-34484+5 CVEs60
HackDHS program accepts reports of Log4jSecurity Affairs·Dec 23, 10:04 UTC · Dec 23, 2021Exploit / PoC in the wildCVE-2021-44228CVE-2021-4504660
IoT Supply Chain Bug Hits Millions of CamerasInfosecurity Magazine·Jun 16, 09:37 UTC · Jun 16, 2021Exploit / PoC60
Google Docs bug could have allowed hackers to hijack screenshotsSecurity Affairs·Dec 30, 16:01 UTC · Dec 30, 2020Exploit / PoC45
NSA Warns Russian Hacker Exploiting VMware Bug to Breach Corporate NetworksThe Hacker News·Dec 8, 05:44 UTC · Dec 8, 2020Exploit / PoC in the wildCVE-2020-400660
Hijacking nearby Firefox mobile browsers via WiFi by exploiting a bugSecurity Affairs·Sep 19, 18:29 UTC · Sep 19, 2020Exploit / PoC45
Experts Urge Immediate Patching of Wormable DNS Server BugInfosecurity Magazine·Jul 15, 10:17 UTC · Jul 15, 2020Exploit / PoC in the wildCVE-2020-1350CVE-2020-134660
100k+ WordPress sites exposed to hack due to a bug in RealSecurity Affairs·Apr 28, 09:03 UTC · Apr 28, 2020Exploit / PoC in the wild60
New Wi-Fi chip bug affects everything from Amazon's Echo to home routersCyberScoop·Feb 27, 14:16 UTC · Feb 27, 2020Exploit / PoC in the wild60
Mozilla ups bug bounty rewards to $15,000 on critical sitesCyberScoop·Nov 20, 17:31 UTC · Nov 20, 2019Exploit / PoC60
New Chrome 0-day Bug Under Active AttacksThe Hacker News·Nov 1, 17:41 UTC · Nov 1, 2019Exploit / PoC in the wildCVE-2019-13720CVE-2019-1372160
Expert disclosed passcode bypass bug in iOS 13 a week before its releaseSecurity Affairs·Sep 14, 20:05 UTC · Sep 14, 2019Exploit / PoC45