63 New Flaws (Including 0The Hacker News·Nov 15, 00:00 UTC · Nov 15, 2018Exploit / PoC in the wildCVE-2018-8589CVE-2018-8584CVE-2018-8566+47 CVEs60
CISA adds Apple iOS and iPadOS memory corruption bugs to its Known Exploited Vulnerabilities CatalogSecurity Affairs·Mar 7, 07:59 UTC · Mar 7, 2024Exploit / PoC in the wildCVE-2024-23225CVE-2024-2329660
Copy Fail: New Linux bug enables Root via page‑cache corruptionSecurity Affairs·Apr 30, 18:23 UTC · Apr 30, 2026Exploit / PoCCVE-2026-31431160
Senior Ukrainian cybersecurity officials sacked amid corruption probeCyberScoop·Nov 20, 18:16 UTC · Nov 20, 2023Exploit / PoC in the wild60
Hackers Use Corrupted ZIPs and Office Docs to Evade Antivirus and Email DefensesThe Hacker News·Dec 4, 04:48 UTC · Dec 4, 2024Exploit / PoC60
Talos Identifies Multiple Memory Corruption Issues in QuicktimeCisco Talos·Aug 13, 12:35 UTC · Aug 13, 2015Exploit / PoCCVE-2015-3788CVE-2015-3789CVE-2015-3790+3 CVEs60
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache CorruptionThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-4630060
NGINX Rift: an 18-year-old flaw in the world's most deployed web server just came to lightSecurity Affairs·May 14, 13:30 UTC · May 14, 2026Exploit / PoC in the wildCVE-2026-42945CVE-2026-42946CVE-2026-40701+1 CVEs60
U.S. CISA adds a flaw in Linux Kernel to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 4, 10:26 UTC · May 4, 2026Exploit / PoC in the wildCVE-2026-3143160
DarkSword iOS Exploit Kit Uses 6 Flaws, 3 ZeroThe Hacker News·Mar 23, 17:42 UTC · Mar 23, 2026Exploit / PoCCVE-2026-20700CVE-2025-43529CVE-2025-14174+3 CVEs60
Apple urges iPhone users to update as Coruna and DarkSword exploit kits emergeSecurity Affairs·Mar 20, 11:22 UTC · Mar 20, 2026Exploit / PoCCVE-2021-30952CVE-2022-48503CVE-2023-43000+15 CVEs160
DarkSword emerges as powerful iOS exploit tool in global attacksSecurity Affairs·Mar 19, 14:09 UTC · Mar 19, 2026Exploit / PoCCVE-2025-31277CVE-2026-20700CVE-2025-43529+3 CVEs60
Apple discloses first actively exploited zeroCyberScoop·Feb 12, 23:48 UTC · Feb 12, 2026Exploit / PoC in the wildCVE-2026-20700CVE-2025-14174CVE-2025-4352960
Qualcomm fixed three zero-days exploited in limited, targeted attacksSecurity Affairs·Jun 2, 15:52 UTC · Jun 2, 2025Exploit / PoC in the wildCVE-2025-21479CVE-2025-21480CVE-2025-27038+1 CVEs60
August 2018 Microsoft Patch Tuesday fixes two flaws exploited in attacks in the wildSecurity Affairs·Aug 15, 08:40 UTC · Aug 15, 2018Exploit / PoC in the wildCVE-2018-8373CVE-2018-8414CVE-2018-8273+5 CVEs60
Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape AttacksSecurity Affairs·Jul 7, 07:07 UTC · Jul 7, 2026Exploit / PoCCVE-2026-53359CVE-2026-46316CVE-2026-43284+1 CVEs60
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026The Hacker News·Mar 21, 08:25 UTC · Mar 21, 2026Exploit / PoC in the wildCVE-2025-31277CVE-2025-43510CVE-2025-43520+2 CVEs160
Apple fixed first actively exploited zeroSecurity Affairs·Feb 12, 10:50 UTC · Feb 12, 2026Exploit / PoC in the wildCVE-2026-20700CVE-2025-14174CVE-2025-4352960
U.S. CISA adds HPE OneView and Microsoft Office PowerPoint flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 8, 10:43 UTC · Jan 8, 2026Exploit / PoC in the wildCVE-2009-0556CVE-2025-37164160
Google fixed the seventh Chrome zeroSecurity Affairs·Nov 18, 08:59 UTC · Nov 18, 2025Exploit / PoC in the wildCVE-2025-13223CVE-2025-13224CVE-2025-10585+5 CVEs60
Google fixed two Qualcomm bugs that were actively exploited in the wildSecurity Affairs·Aug 6, 06:03 UTC · Aug 6, 2025Exploit / PoC in the wildCVE-2025-21479CVE-2025-27038CVE-2025-21480+1 CVEs60
U.S. CISA adds Multiple Qualcomm chipsets flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jun 4, 09:16 UTC · Jun 4, 2025Exploit / PoC in the wildCVE-2025-21479CVE-2025-21480CVE-2025-2703860
Expert released PoC code for critical Microsoft Word RCE flawSecurity Affairs·Mar 7, 15:04 UTC · Mar 7, 2023Exploit / PoCCVE-2023-21716260
Hundreds of Twitter accounts aimed to suppress vote weeks before Honduran presidential electionCyberScoop·Nov 10, 14:00 UTC · Nov 10, 2021Exploit / PoC in the wild60
Google Hacker Details Zero-Click 'Wormable' WiThe Hacker News·Dec 2, 13:22 UTC · Dec 2, 2020Exploit / PoC in the wildCVE-2020-3843CVE-2020-2795060
Three out of the four flaws fixed with iOS 12.1.4 were exploited in the wildSecurity Affairs·Feb 8, 11:35 UTC · Feb 8, 2019Exploit / PoC in the wildCVE-2019-7287CVE-2019-728660
Windows SMB Zero-Day Exploit Released in the Wild after Microsoft delayed the PatchThe Hacker News·Feb 6, 02:09 UTC · Feb 6, 2017Exploit / PoC60
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become RootSecurity Affairs·Aug 5, 14:24 UTC · Aug 5, 2026Exploit / PoCCVE-2026-6453160
AI is getting better at election facts, but voters shouldn’t rely on itCyberScoop·Aug 5, 09:00 UTC · Aug 5, 2026Exploit / PoC in the wild60
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits AndroidThe Hacker News·Jul 3, 19:41 UTC · Jul 3, 2026Exploit / PoC in the wildCVE-2026-46242CVE-2026-43074CVE-2026-31431+2 CVEs160
Public PoC Released for Critical libssh2 CVE-2026-55200 ClientThe Hacker News·Jun 29, 07:06 UTC · Jun 29, 2026Exploit / PoC in the wildCVE-2026-55200CVE-2019-3855CVE-2026-55199+1 CVEs160
Anthropic's new AI model finds and exploits zero-days across every major OS and browserHelp Net Security·Jun 19, 12:14 UTC · Jun 19, 2026Exploit / PoC in the wildCVE-2026-474760
Microsoft Confirms RoguePlanet ZeroSecurity Affairs·Jun 18, 09:21 UTC · Jun 18, 2026Exploit / PoCCVE-2026-50656CVE-2026-33825CVE-2026-45498+1 CVEs60
U.S. CISA adds Qualcomm and Broadcom VMware Aria Operations flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 4, 08:56 UTC · Mar 4, 2026Exploit / PoC in the wildCVE-2026-22719CVE-2026-2138560
Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the WildThe Hacker News·Feb 10, 14:22 UTC · Feb 10, 2026Exploit / PoC in the wildCVE-2025-43529CVE-2025-14174CVE-2025-24085+6 CVEs60
Google fixed a new actively exploited Chrome zeroSecurity Affairs·Dec 11, 18:19 UTC · Dec 11, 2025Exploit / PoC in the wildCVE-2025-14372CVE-2025-14373CVE-2025-6554+6 CVEs60
U.S. CISA adds a Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 19, 21:12 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2025-1322360
UN seeks to build consensus on ‘safe, secure and trustworthy’ AICyberScoop·Sep 26, 20:31 UTC · Sep 26, 2025Exploit / PoC in the wild60
Apple backports fix for actively exploited CVE-2025Security Affairs·Sep 17, 05:24 UTC · Sep 17, 2025Exploit / PoC in the wildCVE-2025-43300CVE-2025-5517760