Australia Alerts Organizations to Ongoing CMS Exploitation AttacksSecurity Affairs·Jul 13, 07:39 UTC · Jul 13, 2026Exploit / PoC in the wildCVE-2025-34085CVE-2020-36847CVE-2025-12057+15 CVEs60
Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely CompromisedThe Hacker News·Apr 29, 10:40 UTC · Apr 29, 2025Exploit / PoC in the wildCVE-2024-58136CVE-2024-4990CVE-2025-32432+1 CVEs60
U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 22, 14:40 UTC · Mar 22, 2026Exploit / PoC in the wildCVE-2025-31277CVE-2025-32432CVE-2025-43510+3 CVEs60
U.S. CISA adds Sitecore CMS and XP, and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 27, 12:31 UTC · Mar 27, 2025Exploit / PoC in the wildCVE-2019-9875CVE-2019-9874CVE-2025-3015460
U.S. CISA adds ASUS RT-AX55 devices, Craft CMS, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 3, 19:35 UTC · Jun 3, 2025Exploit / PoC in the wildCVE-2021-32030CVE-2023-39780CVE-2024-56145+2 CVEs60
Attackers behind CMS portal breach used legit accounts to swipe dataCyberScoop·Nov 9, 18:56 UTC · Nov 9, 2018Exploit / PoC in the wild60
May 2026 CVE LandscapeRecorded Future·Jun 15, 00:00 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2008-4250CVE-2009-1537CVE-2009-3459+19 CVEs60
U.S. CISA adds Craft CMS and Palo Alto Networks PAN-OS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 21, 10:40 UTC · Feb 21, 2025Exploit / PoC in the wildCVE-2025-23209CVE-2025-0111CVE-2025-0108+1 CVEs60
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026The Hacker News·Mar 21, 08:25 UTC · Mar 21, 2026Exploit / PoC in the wildCVE-2025-31277CVE-2025-43510CVE-2025-43520+2 CVEs160
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as ZeroThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC in the wildCVE-2026-48939CVE-2026-56291CVE-2025-6389+9 CVEs60
Two New Security Flaws Reported in Ghost CMS Blogging SoftwareThe Hacker News·Dec 23, 11:36 UTC · Dec 23, 2022Exploit / PoC in the wildCVE-2022-41654CVE-2022-4169760
Critical WordPress REST API Bug: Prevent Your Blog From Being Hacked!The Hacker News·Feb 2, 08:24 UTC · Feb 2, 2017Exploit / PoC in the wild60
U.S. CISA adds Yii Framework and Commvault Command Center flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 3, 10:11 UTC · May 3, 2025Exploit / PoC in the wildCVE-2025-34028CVE-2024-58136CVE-2025-32432260
⚡ Weekly Recap: Instagram Account Hacks, Android ZeroThe Hacker News·Jun 9, 05:53 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2025-48595CVE-2026-28318CVE-2026-39210+43 CVEs60
Samsung MagicINFO flaw exploited days after PoC publicationSecurity Affairs·May 6, 17:54 UTC · May 6, 2025Exploit / PoC in the wildCVE-2024-739960
Thousands of Adobe Commerce e-stores hacked by exploiting CosmicSting bugSecurity Affairs·Oct 3, 14:36 UTC · Oct 3, 2024Exploit / PoC in the wildCVE-2024-34102CVE-2024-296160
Microsoft fixed Azure AD bug that led to Bing.com results manipulation and account takeoverSecurity Affairs·Apr 3, 11:32 UTC · Apr 3, 2023Exploit / PoC in the wild160
Chinese APT exploited Sophos Firewall ZeroSecurity Affairs·Jun 17, 23:00 UTC · Jun 17, 2022Exploit / PoC in the wildCVE-2022-1040CVE-2022-2613460
US CISA added 17 flaws to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Jan 23, 18:13 UTC · Jan 23, 2022Exploit / PoC in the wildCVE-2021-32648CVE-2021-21315CVE-2021-21975+14 CVEs160
CISA adds Log4Shell flaw to the Known Exploited Vulnerabilities CatalogSecurity Affairs·Dec 13, 13:44 UTC · Dec 13, 2021Exploit / PoC in the wildCVE-2021-44228CVE-2021-44515CVE-2021-44168+10 CVEs60
Over 115,000 Drupal Sites Still Vulnerable to Drupalgeddon2 ExploitThe Hacker News·Jun 5, 08:06 UTC · Jun 5, 2018Exploit / PoC in the wildCVE-2018-760060
Just 1% of AI-Discovered Vulnerabilities Exploited in the WildInfosecurity Magazine·Jul 29, 10:15 UTC · Jul 29, 2026Exploit / PoC in the wild60
Researchers Build WordPress Exploit Using OpenAI's GPTInfosecurity Magazine·Jul 20, 14:00 UTC · Jul 20, 2026Exploit / PoC in the wildCVE-2026-63030CVE-2026-6013760
U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 25, 21:01 UTC · Apr 25, 2026Exploit / PoC in the wildCVE-2024-7399CVE-2024-57726CVE-2024-57728+1 CVEs60
U.S. CISA adds Adobe, Fortinet, Microsoft Windows, Microsoft Exchange Server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 14, 07:38 UTC · Apr 14, 2026Exploit / PoC in the wildCVE-2026-34621CVE-2012-1854CVE-2020-9715+4 CVEs260
Zero-Day Exploits Surge, 30% of Flaws Attacked Before DisclosureInfosecurity Magazine·Jan 22, 12:45 UTC · Jan 22, 2026Exploit / PoC in the wild60
U.S. CISA adds Oracle, Windows, Kentico, Apple flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 21, 14:10 UTC · Oct 21, 2025Exploit / PoC in the wildCVE-2022-48503CVE-2025-2746CVE-2025-2747+3 CVEs60
Third of Exploited Flaws Weaponized Within a Day of DisclosureInfosecurity Magazine·Jul 30, 12:45 UTC · Jul 30, 2025Exploit / PoC in the wild60
U.S. CISA adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 12, 09:17 UTC · Jun 12, 2025Exploit / PoC in the wildCVE-2025-24016CVE-2025-3305360
Two flaws in vBulletin forum software are under attackSecurity Affairs·Jun 1, 13:50 UTC · Jun 1, 2025Exploit / PoC in the wildCVE-2025-48827CVE-2025-4882860
How HHS has strengthened cybersecurity of hospitals and health care systemsCyberScoop·Jan 17, 11:00 UTC · Jan 17, 2025Exploit / PoC in the wild60
CISA Puts Chrome and Magento Zero-Days on MustInfosecurity Magazine·Feb 16, 09:41 UTC · Feb 16, 2022Exploit / PoC in the wildCVE-2022-24086CVE-2022-060960
Ukrainian government websites hacked amid rising regional security anxietyCyberScoop·Jan 14, 14:51 UTC · Jan 14, 2022Exploit / PoC in the wild60
February 2021 Patch Tuesday: Microsoft and Adobe fix exploited zero-daysHelp Net Security·Jun 8, 18:29 UTC · Jun 8, 2021Exploit / PoC in the wildCVE-2021-21017CVE-2021-1732CVE-2021-24074+6 CVEs60
Boing Boing says hacker got around 2FA in breaching its content management systemCyberScoop·Jan 13, 21:56 UTC · Jan 13, 2020Exploit / PoC in the wild60
Latest WinRAR, Drupal flaws under active exploitationHelp Net Security·Feb 26, 00:00 UTC · Feb 26, 2019Exploit / PoC in the wildCVE-2018-20250CVE-2019-634060
Hackers compromise WordPress sites via ZeroSecurity Affairs·Jan 28, 15:26 UTC · Jan 28, 2019Exploit / PoC in the wildCVE-2019-670360
Zero-Day flaws in 3 WordPress Plugins being exploited in the wildSecurity Affairs·Oct 3, 14:05 UTC · Oct 3, 2017Exploit / PoC in the wild60
WordPress kept users and hackers in the dark while secretly fixing critical zero-dayHelp Net Security·Feb 2, 00:00 UTC · Feb 2, 2017Exploit / PoC in the wild60