Chinese hackers exploiting React2Shell bug impacting countless websites, Amazon researchers sayThe Record·Dec 5, 16:22 UTC · Dec 5, 2025Exploit / PoC in the wildCVE-2025-5518260
Samsung Mobile Flaw Exploited as ZeroThe Hacker News·Nov 11, 11:21 UTC · Nov 11, 2025Exploit / PoC in the wildCVE-2025-21042CVE-2025-21043CVE-2025-55177+1 CVEs60
Mem3nt0 moriKaspersky Securelist·Oct 27, 03:00 UTC · Oct 27, 2025Exploit / PoC in the wildCVE-2025-278360
After SharePoint attacks, Microsoft stops sharing PoC exploit code with ChinaSecurity Affairs·Aug 22, 09:12 UTC · Aug 22, 2025Exploit / PoC in the wild160
CISA Adds Citrix NetScaler CVE-2025-5777 to KEV Catalog as Active Exploits Target EnterprisesThe Hacker News·Jul 18, 04:54 UTC · Jul 18, 2025Exploit / PoC in the wildCVE-2025-5777CVE-2023-4966CVE-2025-6543+1 CVEs60
U.S. CISA adds Wing FTP Server flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 16, 00:01 UTC · Jul 16, 2025Exploit / PoC in the wildCVE-2025-4781260
U.S. CISA adds Cisco Smart Licensing Utility flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 31, 19:56 UTC · Mar 31, 2025Exploit / PoC in the wildCVE-2024-20439CVE-2024-20440CVE-2024-030560
Apple fixes iPhone and iPad bug actively exploited in ‘extremely sophisticated attacks’Security Affairs·Feb 10, 23:53 UTC · Feb 10, 2025Exploit / PoC in the wildCVE-2025-24200CVE-2023-41064CVE-2023-41061+1 CVEs60
U.S. CISA adds Microsoft Windows, Apache HugeGraph-Server, Oracle JDeveloper, Oracle WebLogic Server, and Microsoft SQL Server bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 19, 15:48 UTC · Sep 19, 2024Exploit / PoC in the wildCVE-2024-27348CVE-2020-0618CVE-2019-1069+2 CVEs60
Microsoft Zero-Day CVE-2024-38193 was exploited by North KoreaSecurity Affairs·Aug 19, 08:41 UTC · Aug 19, 2024Exploit / PoC in the wildCVE-2024-38193CVE-2024-2133860
CISA adds Cisco NX-OS Command Injection bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 8, 07:16 UTC · Jul 8, 2024Exploit / PoC in the wildCVE-2024-2039960
Check Point VPN zero-day exploited since beginning of April (CVE-2024-24919)Help Net Security·Jun 5, 08:26 UTC · Jun 5, 2024Exploit / PoC in the wildCVE-2024-2491960
CISA adds Palo Alto Networks PAN-OS Command Injection flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 25, 13:23 UTC · Apr 25, 2024Exploit / PoC in the wildCVE-2024-340060
CISA adds Looney Tunables Linux bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 22, 10:35 UTC · Nov 22, 2023Exploit / PoC in the wildCVE-2023-4911CVE-2017-984160
Zimbra zero-day exploited to steal government emails by 4 groupsSecurity Affairs·Nov 16, 20:49 UTC · Nov 16, 2023Exploit / PoCCVE-2023-3758060
Exploit writers invited to probe Chrome's V8 engine, Google Cloud's KVMHelp Net Security·Oct 9, 00:00 UTC · Oct 9, 2023Exploit / PoC in the wild60
CISA adds flaw in Citrix ShareFile to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 18, 17:45 UTC · Aug 18, 2023Exploit / PoC in the wildCVE-2023-2448960
CISA adds actively exploited flaw in .NET, Visual Studio to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 10, 08:28 UTC · Aug 10, 2023Exploit / PoC in the wildCVE-2023-3818060
2022 Witnessed A Drop In Exploited Zero-DaysHelp Net Security·Mar 21, 00:00 UTC · Mar 21, 2023Exploit / PoC in the wild60
Fortinet FortiNAC CVE-2022-39952 flaw exploited in the wild hours after release of PoC exploitSecurity Affairs·Feb 23, 19:45 UTC · Feb 23, 2023Exploit / PoC in the wildCVE-2022-39952CVE-2021-4275660
Spring confirms ‘Spring4Shell’ zeroThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoCCVE-2022-22965CVE-2022-2296360
US CISA adds MS Exchange bug CVE-2022-41080 to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Jan 11, 10:49 UTC · Jan 11, 2023Exploit / PoC in the wildCVE-2022-41080CVE-2022-41082CVE-2022-41040+1 CVEs60
MysterySnail attacks with Windows zeroKaspersky Securelist·Oct 13, 14:49 UTC · Oct 13, 2021Exploit / PoCCVE-2016-3309CVE-2021-4044960
Apple fixes actively exploited FORCEDENTRY zeroSecurity Affairs·Sep 13, 20:27 UTC · Sep 13, 2021Exploit / PoC in the wildCVE-2021-30860CVE-2021-3085860
Exploit broker Zerodium is looking for VMware vCenter Server exploitsSecurity Affairs·Jul 15, 18:28 UTC · Jul 15, 2021Exploit / PoC60
Google: four zero-day flaws have been exploited in the wildSecurity Affairs·Jul 14, 21:25 UTC · Jul 14, 2021Exploit / PoC in the wildCVE-2021-1879CVE-2021-21166CVE-2021-30551+1 CVEs60
February 2021 Patch Tuesday: Microsoft and Adobe fix exploited zero-daysHelp Net Security·Jun 8, 18:29 UTC · Jun 8, 2021Exploit / PoC in the wildCVE-2021-21017CVE-2021-1732CVE-2021-24074+6 CVEs60
Zero-day vulnerability in Desktop Window Manager (CVE-2021Kaspersky Securelist·Apr 13, 17:35 UTC · Apr 13, 2021Exploit / PoC in the wildCVE-2021-1732CVE-2021-2831060
New 0-Day Flaw Affecting Most Android Phones Being Exploited in the WildThe Hacker News·Oct 4, 09:12 UTC · Oct 4, 2019Exploit / PoC in the wildCVE-2019-221560
Researchers published the PoC exploit code for Linux SystemD bugsSecurity Affairs·Jan 31, 13:55 UTC · Jan 31, 2019Exploit / PoCCVE-2018-16864CVE-2018-16865CVE-2018-1686650
0x20k of Ghost Squad released ODay Exploit Targeting Apache HadoopSecurity Affairs·Nov 1, 14:34 UTC · Nov 1, 2018Exploit / PoC60
Let It Ride: The Sofacy Group’s DealersChoice Attacks ContinuePalo Alto Unit 42·Nov 1, 10:41 UTC · Nov 1, 2018Exploit / PoC in the wildCVE-2016-7855CVE-2016-7255CVE-2015-7645160
May 2018 Patch Tuesday: Microsoft fixes 2 zero-day flaws reportedly exploited by APT groupSecurity Affairs·May 9, 08:09 UTC · May 9, 2018Exploit / PoC in the wildCVE-2018-8174CVE-2018-8120CVE-2018-8170+1 CVEs60
Zerodium is offers $1 Million for Tor Browser ExploitsSecurity Affairs·Nov 4, 09:24 UTC · Nov 4, 2017Exploit / PoC60
Zero-day market, the governments are the main buyersSecurity Affairs·Oct 17, 09:08 UTC · Oct 17, 2017Exploit / PoC60
BlackOasis APT leverages new Flash zeroSecurity Affairs·Oct 17, 07:05 UTC · Oct 17, 2017Exploit / PoC in the wildCVE-2017-11292CVE-2017-8759CVE-2015-5119+2 CVEs60
BlackOasis APT and new targeted attacks leveraging zeroKaspersky Securelist·Oct 16, 14:28 UTC · Oct 16, 2017Exploit / PoC in the wildCVE-2017-11292CVE-2017-8759CVE-2016-4117+2 CVEs60
Software flaw that allowed Stuxnet virus to spread was the most exploited in 2016CyberScoop·Apr 21, 15:10 UTC · Apr 21, 2017Exploit / PoC in the wildCVE-2010-256860
Firefox Zero-Day Exploit to Unmask Tor Users Released OnlineThe Hacker News·Nov 30, 08:49 UTC · Nov 30, 2016Exploit / PoC in the wild60
Windows zero-day exploit used in targeted attacks by FruityArmor APTKaspersky Securelist·Oct 20, 08:56 UTC · Oct 20, 2016Exploit / PoCCVE-2016-3393CVE-2016-1010CVE-2016-4171+1 CVEs60