Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely CompromisedThe Hacker News·Apr 29, 10:40 UTC · Apr 29, 2025Exploit / PoC in the wildCVE-2024-58136CVE-2024-4990CVE-2025-32432+1 CVEs60
U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 22, 14:40 UTC · Mar 22, 2026Exploit / PoC in the wildCVE-2025-31277CVE-2025-32432CVE-2025-43510+3 CVEs60
Attackers behind CMS portal breach used legit accounts to swipe dataCyberScoop·Nov 9, 18:56 UTC · Nov 9, 2018Exploit / PoC in the wild60
May 2026 CVE LandscapeRecorded Future·Jun 15, 00:00 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2008-4250CVE-2009-1537CVE-2009-3459+19 CVEs60
U.S. CISA adds Craft CMS and Palo Alto Networks PAN-OS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 21, 10:40 UTC · Feb 21, 2025Exploit / PoC in the wildCVE-2025-23209CVE-2025-0111CVE-2025-0108+1 CVEs60
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026The Hacker News·Mar 21, 08:25 UTC · Mar 21, 2026Exploit / PoC in the wildCVE-2025-31277CVE-2025-43510CVE-2025-43520+2 CVEs160
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as ZeroThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC in the wildCVE-2026-48939CVE-2026-56291CVE-2025-6389+9 CVEs60
Two New Security Flaws Reported in Ghost CMS Blogging SoftwareThe Hacker News·Dec 23, 11:36 UTC · Dec 23, 2022Exploit / PoC in the wildCVE-2022-41654CVE-2022-4169760
Critical WordPress REST API Bug: Prevent Your Blog From Being Hacked!The Hacker News·Feb 2, 08:24 UTC · Feb 2, 2017Exploit / PoC in the wild60
Zero-day Content Injection Vulnerability found in WordPressSecurity Affairs·Feb 2, 07:12 UTC · Feb 2, 2017Exploit / PoC60
Kaspersky DDoS Intelligence Report for Q4 2015Kaspersky Securelist·Jan 28, 12:00 UTC · Jan 28, 2016Exploit / PoC60
Thousands of Adobe Commerce e-stores hacked by exploiting CosmicSting bugSecurity Affairs·Oct 3, 14:36 UTC · Oct 3, 2024Exploit / PoC in the wildCVE-2024-34102CVE-2024-296160
Microsoft fixed Azure AD bug that led to Bing.com results manipulation and account takeoverSecurity Affairs·Apr 3, 11:32 UTC · Apr 3, 2023Exploit / PoC in the wild160
Chinese APT exploited Sophos Firewall ZeroSecurity Affairs·Jun 17, 23:00 UTC · Jun 17, 2022Exploit / PoC in the wildCVE-2022-1040CVE-2022-2613460
US CISA added 17 flaws to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Jan 23, 18:13 UTC · Jan 23, 2022Exploit / PoC in the wildCVE-2021-32648CVE-2021-21315CVE-2021-21975+14 CVEs160
CISA adds Log4Shell flaw to the Known Exploited Vulnerabilities CatalogSecurity Affairs·Dec 13, 13:44 UTC · Dec 13, 2021Exploit / PoC in the wildCVE-2021-44228CVE-2021-44515CVE-2021-44168+10 CVEs60
Researcher discloses exploit code for a vBulletin zeroSecurity Affairs·Aug 11, 08:14 UTC · Aug 11, 2020Exploit / PoCCVE-2019-1675960
Over 115,000 Drupal Sites Still Vulnerable to Drupalgeddon2 ExploitThe Hacker News·Jun 5, 08:06 UTC · Jun 5, 2018Exploit / PoC in the wildCVE-2018-760060
Experts are observing Drupalgeddon2 (CVE-2018Security Affairs·Apr 19, 04:02 UTC · Apr 19, 2018Exploit / PoCCVE-2018-7600CVE-2017-1027160
Drupal addressed the critical CVE-2018Security Affairs·Mar 29, 12:24 UTC · Mar 29, 2018Exploit / PoCCVE-2018-7600CVE-2014-370460
Recent WordPress flaw exploited to deface more than 1.5 million web sitesSecurity Affairs·Feb 11, 09:11 UTC · Feb 11, 2017Exploit / PoC60
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM MemoryThe Hacker News·Aug 6, 11:30 UTC · Aug 6, 2026Exploit / PoC60
Just 1% of AI-Discovered Vulnerabilities Exploited in the WildInfosecurity Magazine·Jul 29, 10:15 UTC · Jul 29, 2026Exploit / PoC in the wild60
Researchers Build WordPress Exploit Using OpenAI's GPTInfosecurity Magazine·Jul 20, 14:00 UTC · Jul 20, 2026Exploit / PoC in the wildCVE-2026-63030CVE-2026-6013760
U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 25, 21:01 UTC · Apr 25, 2026Exploit / PoC in the wildCVE-2024-7399CVE-2024-57726CVE-2024-57728+1 CVEs60
U.S. CISA adds Adobe, Fortinet, Microsoft Windows, Microsoft Exchange Server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 14, 07:38 UTC · Apr 14, 2026Exploit / PoC in the wildCVE-2026-34621CVE-2012-1854CVE-2020-9715+4 CVEs260
Zero-Day Exploits Surge, 30% of Flaws Attacked Before DisclosureInfosecurity Magazine·Jan 22, 12:45 UTC · Jan 22, 2026Exploit / PoC in the wild60
U.S. CISA adds Oracle, Windows, Kentico, Apple flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 21, 14:10 UTC · Oct 21, 2025Exploit / PoC in the wildCVE-2022-48503CVE-2025-2746CVE-2025-2747+3 CVEs60
Third of Exploited Flaws Weaponized Within a Day of DisclosureInfosecurity Magazine·Jul 30, 12:45 UTC · Jul 30, 2025Exploit / PoC in the wild60
U.S. CISA adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 12, 09:17 UTC · Jun 12, 2025Exploit / PoC in the wildCVE-2025-24016CVE-2025-3305360
Two flaws in vBulletin forum software are under attackSecurity Affairs·Jun 1, 13:50 UTC · Jun 1, 2025Exploit / PoC in the wildCVE-2025-48827CVE-2025-4882860
How HHS has strengthened cybersecurity of hospitals and health care systemsCyberScoop·Jan 17, 11:00 UTC · Jan 17, 2025Exploit / PoC in the wild60
Critical flaw in WPML WordPress plugin impacts 1M websitesSecurity Affairs·Aug 27, 21:38 UTC · Aug 27, 2024Exploit / PoCCVE-2024-638660
Expert found critical flaws in OpenText ECM SystemSecurity Affairs·Jan 22, 18:51 UTC · Jan 22, 2023Exploit / PoCCVE-2022-45924CVE-2022-45922CVE-2022-45925+4 CVEs160
Zerodium looks to buy zero-days in Outlook and Thunderbird email clientsThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoC60
Zerodium acquiring zero-days in Pidgin, an IM client popular with cybercriminalsThe Record·Dec 12, 00:00 UTC · Dec 12, 2022Exploit / PoC60
Zero Day attacks target online stores using PrestaShopSecurity Affairs·Jul 26, 06:23 UTC · Jul 26, 2022Exploit / PoCCVE-2022-3640860
Chinese Hackers Exploited Sophos Firewall ZeroThe Hacker News·Jun 18, 03:43 UTC · Jun 18, 2022Exploit / PoCCVE-2022-1040CVE-2022-2613460
CISA Puts Chrome and Magento Zero-Days on MustInfosecurity Magazine·Feb 16, 09:41 UTC · Feb 16, 2022Exploit / PoC in the wildCVE-2022-24086CVE-2022-060960
Ukrainian government websites hacked amid rising regional security anxietyCyberScoop·Jan 14, 14:51 UTC · Jan 14, 2022Exploit / PoC in the wild60