Week in review: PoC for FortiSIEM flaw released, Rakuten Viber CISO/CTO on messaging risksHelp Net Security·Jan 18, 00:00 UTC · Jan 18, 2026Exploit / PoCCVE-2025-64155CVE-2025-20393160
Google Hacker Discloses New Linux Kernel Vulnerability and PoC ExploitThe Hacker News·Sep 28, 08:35 UTC · Sep 28, 2018Exploit / PoCCVE-2018-1718260
Critical flaw in Linux APT package manager could allow remote hackSecurity Affairs·Jan 22, 21:00 UTC · Jan 22, 2019Exploit / PoCCVE-2019-346260
Unprivileged users could exploit AppArmor bugs to gain root accessSecurity Affairs·Mar 16, 08:05 UTC · Mar 16, 2026Exploit / PoC60
Week in review: PoC for Trend Micro Apex Central RCE released, Patch Tuesday forecastHelp Net Security·Jan 11, 00:00 UTC · Jan 11, 2026Exploit / PoC in the wildCVE-2025-69258CVE-2025-3716460
CISA adds Chrome, Redis bugs to Known Exploited Vulnerabilities CatalogSecurity Affairs·Mar 29, 07:56 UTC · Mar 29, 2022Exploit / PoC in the wildCVE-2022-1096CVE-2022-0543CVE-2022-21999+1 CVEs60
Zerodium offers up to $500,000 for Linux ZeroSecurity Affairs·Jul 1, 12:29 UTC · Jul 1, 2018Exploit / PoC60
$45,000 bounty offered for Linux zero daysCyberScoop·Feb 8, 17:37 UTC · Feb 8, 2018Exploit / PoC in the wild60
Dirty COW — Critical Linux Kernel Flaw Being Exploited in the WildThe Hacker News·Oct 25, 15:07 UTC · Oct 25, 2016Exploit / PoC in the wildCVE-2016-519560
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux HostsThe Hacker News·Aug 6, 17:58 UTC · Aug 6, 2026Exploit / PoC in the wildCVE-2026-64561CVE-2026-53359CVE-2026-4631660
OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become RootSecurity Affairs·Aug 5, 14:24 UTC · Aug 5, 2026Exploit / PoCCVE-2026-6453160
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsThe Hacker News·Jul 31, 11:17 UTC · Jul 31, 2026Exploit / PoC in the wildCVE-2026-66066CVE-2025-24293160
AI-Assisted Bug Hunt Uncovers Linux Kernel 0Infosecurity Magazine·Jul 28, 14:45 UTC · Jul 28, 2026Exploit / PoCCVE-2026-53264CVE-2026-6430060
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 SystemsThe Hacker News·Jul 7, 04:58 UTC · Jul 7, 2026Exploit / PoCCVE-2026-53359CVE-2026-43284CVE-2026-43500+2 CVEs60
Public PoC Released for Critical libssh2 CVE-2026-55200 ClientThe Hacker News·Jun 29, 07:06 UTC · Jun 29, 2026Exploit / PoC in the wildCVE-2026-55200CVE-2019-3855CVE-2026-55199+1 CVEs160
Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, OpenThe Hacker News·Jun 9, 11:59 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2026-39987CVE-2026-31431CVE-2026-43284+1 CVEs160
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache CorruptionThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-4630060
Apache fixes critical HTTP/2 double-free flaw CVE-2026Security Affairs·May 6, 11:00 UTC · May 6, 2026Exploit / PoCCVE-2026-23918160
Critical Apache HTTP/2 Flaw (CVE-2026The Hacker News·May 5, 16:46 UTC · May 5, 2026Exploit / PoCCVE-2026-2391860
Zero-Day Flaw in Linux Kernel Found by AIInfosecurity Magazine·May 1, 10:45 UTC · May 1, 2026Exploit / PoCCVE-2026-3143160
Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container IsolationThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Exploit / PoC60
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network PlatformsThe Hacker News·Feb 11, 13:28 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-0488CVE-2026-0509CVE-2025-32007+4 CVEs60
U.S. CISA adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 27, 14:54 UTC · Jan 27, 2026Exploit / PoC in the wildCVE-2018-14634CVE-2025-52691CVE-2026-21509+2 CVEs60
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs60
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel ZeroThe Hacker News·Nov 12, 11:14 UTC · Nov 12, 2025Exploit / PoC in the wildCVE-2025-62215CVE-2025-60724CVE-2025-62220+1 CVEs60
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever ShippedThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Exploit / PoC in the wildCVE-2025-24990CVE-2025-59230CVE-2025-47827+5 CVEs160
catdoc zero-day, NVIDIA, High-Logic FontCreator and Parallel vulnerabilitiesCisco Talos·Jun 11, 14:03 UTC · Jun 11, 2025Exploit / PoCCVE-2024-48877CVE-2024-52035CVE-2024-54028+6 CVEs60
Focus on what matters most: Exposure management and your attack surfaceHelp Net Security·Apr 8, 17:17 UTC · Apr 8, 2025Exploit / PoCCVE-2024-340060
Meta warns of actively exploited flaw in FreeType librarySecurity Affairs·Mar 13, 11:02 UTC · Mar 13, 2025Exploit / PoC in the wildCVE-2025-2736360
3 Actively Exploited Zero-Day Flaws Patched in Microsoft's Latest Security UpdateThe Hacker News·Jan 21, 15:30 UTC · Jan 21, 2025Exploit / PoC in the wildCVE-2024-7344CVE-2025-21333CVE-2025-21334+13 CVEs60
Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler BugsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-21410+6 CVEs260
Microsoft Issues Security Update Fixing 118 Flaws, Two Actively Exploited in the WildThe Hacker News·Oct 9, 12:48 UTC · Oct 9, 2024Exploit / PoC in the wildCVE-2024-43572CVE-2024-43573CVE-2024-43583+7 CVEs60
Printer bug sends researchers into uproar, affects major Linux distrosCyberScoop·Sep 27, 11:41 UTC · Sep 27, 2024Exploit / PoCCVE-2024-47176CVE-2024-47076CVE-2024-47175+1 CVEs60
Focus on What Matters Most: Exposure Management and Your Attack SurfaceThe Hacker News·Aug 23, 10:55 UTC · Aug 23, 2024Exploit / PoCCVE-2024-340060
Critical Ghostscript flaw exploited in the wild. Patch it now!Security Affairs·Jul 8, 18:12 UTC · Jul 8, 2024Exploit / PoC in the wildCVE-2024-29510CVE-2024-29509CVE-2024-29506+3 CVEs60
HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS AttacksThe Hacker News·Oct 26, 10:49 UTC · Oct 26, 2023Exploit / PoCCVE-2023-4448760
Google "confirms" that exploited Chrome zero-day is actually in libwebp (CVE-2023-5129)Help Net Security·Sep 29, 10:48 UTC · Sep 29, 2023Exploit / PoC in the wildCVE-2023-5129CVE-2023-4863CVE-2023-4106460
Chrome zero-day exploited in the wild, patch now! (CVE-2023-4863)Help Net Security·Sep 29, 08:22 UTC · Sep 29, 2023Exploit / PoC in the wildCVE-2023-4863CVE-2023-41064CVE-2023-41061+1 CVEs60
A new Chrome 0-day is sending the Internet into a new chapter of Groundhog DayArs Technica · Security·Sep 28, 21:23 UTC · Sep 28, 2023Exploit / PoCCVE-2023-5217CVE-2023-486360
Incomplete disclosures by Apple and Google create “huge blindspot” for 0Ars Technica · Security·Sep 21, 22:19 UTC · Sep 21, 2023Exploit / PoC in the wildCVE-2023-41064CVE-2023-486360