EU, Dutch government announce hacks following Ivanti zeroThe Record·Feb 9, 13:31 UTC · Feb 9, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-134060
U.S. CISA adds Sitecore, Android, and Linux flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 25, 18:23 UTC · Sep 25, 2025Exploit / PoC in the wildCVE-2025-38352CVE-2025-48543CVE-2025-5369060
U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 30, 18:51 UTC · Jun 30, 2025Exploit / PoC in the wildCVE-2025-6543CVE-2023-6548CVE-2023-654960
Hackers exploited Windows 0-day for 6 months after Microsoft knew of itArs Technica · Security·Mar 4, 22:47 UTC · Mar 4, 2024Exploit / PoC in the wildCVE-2024-2133860
CISA adds Microsoft Exchange and Cisco ASA and FTD bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 23, 00:20 UTC · Feb 23, 2024Exploit / PoC in the wildCVE-2020-3259CVE-2024-2141060
CISA Issues Emergency Directive to Federal Agencies on Ivanti ZeroThe Hacker News·Jan 25, 04:22 UTC · Jan 25, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-2188760
Experts demonstrate a post-exploitation tampering technique to display Fake Lockdown modeSecurity Affairs·Dec 6, 12:10 UTC · Dec 6, 2023Exploit / PoC45
January 2021 Patch Tuesday: Microsoft plugs Defender zero-day RCEHelp Net Security·Nov 14, 08:33 UTC · Nov 14, 2023Exploit / PoC in the wildCVE-2021-1647CVE-2021-1648CVE-2021-1658+8 CVEs60
Data centers at risk due to flaws in power management softwareCyberScoop·Aug 14, 14:18 UTC · Aug 14, 2023Exploit / PoC60
Barracuda Urges Immediate Replacement of Hacked ESG AppliancesThe Hacker News·Jun 9, 05:07 UTC · Jun 9, 2023Exploit / PoCCVE-2023-286860
Zero day affecting Fortra’s GoAnywhere file transfer tool is actively being exploitedThe Record·Feb 7, 14:52 UTC · Feb 7, 2023Exploit / PoC60
Dirty Pipe Linux flaw allows gaining root privileges on major distrosSecurity Affairs·Mar 8, 07:54 UTC · Mar 8, 2022Exploit / PoCCVE-2022-0847CVE-2016-519550
NoReboot persistence technique fakes iPhone shutdownSecurity Affairs·Jan 6, 10:45 UTC · Jan 6, 2022Exploit / PoC45
Citrix Workspace flaw can allow remote hack of devices running vulnerable appSecurity Affairs·Jul 22, 11:49 UTC · Jul 22, 2020Exploit / PoCCVE-2020-820760
Firefox 74.0.1 addresses two zeroSecurity Affairs·Apr 4, 16:22 UTC · Apr 4, 2020Exploit / PoC in the wildCVE-2020-6819CVE-2020-6820CVE-2019-1702660
Week in review: Leaking LastPass extensions, 300+ hackable Cisco switchesHelp Net Security·Mar 26, 00:00 UTC · Mar 26, 2017Exploit / PoC60
Hackers can exploit flaws in Samsung Smart Home to access your houseSecurity Affairs·May 3, 05:45 UTC · May 3, 2016Exploit / PoC60
IT threat evolution Q2 2014Kaspersky Securelist·Aug 4, 11:00 UTC · Aug 4, 2014Exploit / PoCCVE-2014-051560
U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 22, 10:23 UTC · Jul 22, 2026Exploit / PoC in the wildCVE-2026-25089CVE-2026-39808CVE-2026-5864460
U.S. CISA adds Wing FTP Server flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 16, 00:01 UTC · Jul 16, 2025Exploit / PoC in the wildCVE-2025-4781260
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026The Hacker News·Jul 17, 06:42 UTC · Jul 17, 2026Exploit / PoC in the wildCVE-2026-58644CVE-2026-32201CVE-2026-45659+3 CVEs60
U.S. CISA adds Microsoft SharePoint and Zimbra flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 18, 21:11 UTC · Mar 18, 2026Exploit / PoC in the wildCVE-2026-20963CVE-2025-6637660
TeamViewer fixes a flaw that allows users sharing a desktop session to gain control of the other’s PCSecurity Affairs·Dec 6, 04:13 UTC · Dec 6, 2017Exploit / PoC45
U.S. CISA adds Microsoft SharePoint flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 23, 13:50 UTC · Oct 23, 2024Exploit / PoC in the wildCVE-2024-3809460
VMware Workspace ONE Access CVE-2022Security Affairs·Apr 14, 10:42 UTC · Apr 14, 2022Exploit / PoC in the wildCVE-2022-2295460
CIGslip attack could allow hacker to bypass Microsoft Code Integrity GuardSecurity Affairs·Mar 9, 10:11 UTC · Mar 9, 2018Exploit / PoC145
Why Everyone Needs to Take the Latest CISA Directive SeriouslyThe Hacker News·Dec 3, 09:23 UTC · Dec 3, 2021Exploit / PoC in the wildCVE-2019-021160
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run CodeThe Hacker News·Jul 24, 04:46 UTC · Jul 24, 2026Exploit / PoC in the wildCVE-2026-1059160
Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious CodeThe Hacker News·May 15, 00:00 UTC · May 15, 2024Exploit / PoC in the wildCVE-2024-25641CVE-2024-29895CVE-2024-31445+4 CVEs60
Flaws in Popup Builder WordPress plugin expose 100K+ websites to hackSecurity Affairs·Mar 13, 11:42 UTC · Mar 13, 2020Exploit / PoC in the wildCVE-2020-10196CVE-2020-1019560
U.S. CISA adds Fortinet products and Ivanti CSA bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 14, 20:47 UTC · Oct 14, 2024Exploit / PoC in the wildCVE-2024-23113CVE-2024-9379CVE-2024-9380+2 CVEs60
ASLR Protection could be bypassed by visiting a website.Millions of devices at riskSecurity Affairs·Feb 17, 11:06 UTC · Feb 17, 2017Exploit / PoCCVE-2017-5925CVE-2017-5926CVE-2017-5927+1 CVEs60
U.S. CISA adds Ivanti CSA and Fortinet bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 10, 11:11 UTC · Oct 10, 2024Exploit / PoC in the wildCVE-2024-23113CVE-2024-9379CVE-2024-9380+2 CVEs60
Hackers Actively Exploiting Citrix ADC and Gateway ZeroThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2022Exploit / PoCCVE-2022-27518CVE-2021-22893CVE-2022-42475+3 CVEs60
FireEye has discovered a watering hole attack based on 0Security Affairs·Aug 27, 08:08 UTC · Aug 27, 2017Exploit / PoCCVE-2014-032260
Three new Ivanti CSA zeroSecurity Affairs·Oct 8, 21:26 UTC · Oct 8, 2024Exploit / PoC in the wildCVE-2024-9379CVE-2024-9380CVE-2024-9381+2 CVEs60
100k+ WordPress sites exposed to hack due to a bug in RealSecurity Affairs·Apr 28, 09:03 UTC · Apr 28, 2020Exploit / PoC in the wild60