29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP RequestsThe Hacker News·Jun 23, 11:30 UTC · Jun 23, 2026Exploit / PoC in the wildCVE-2026-47729CVE-2026-50012160
Week in review: PoC for Trend Micro Apex Central RCE released, Patch Tuesday forecastHelp Net Security·Jan 11, 00:00 UTC · Jan 11, 2026Exploit / PoC in the wildCVE-2025-69258CVE-2025-3716460
CISA adds Looney Tunables Linux bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 22, 10:35 UTC · Nov 22, 2023Exploit / PoC in the wildCVE-2023-4911CVE-2017-984160
CISA adds Chrome, Redis bugs to Known Exploited Vulnerabilities CatalogSecurity Affairs·Mar 29, 07:56 UTC · Mar 29, 2022Exploit / PoC in the wildCVE-2022-1096CVE-2022-0543CVE-2022-21999+1 CVEs60
$45,000 bounty offered for Linux zero daysCyberScoop·Feb 8, 17:37 UTC · Feb 8, 2018Exploit / PoC in the wild60
Dirty COW — Critical Linux Kernel Flaw Being Exploited in the WildThe Hacker News·Oct 25, 15:07 UTC · Oct 25, 2016Exploit / PoC in the wildCVE-2016-519560
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape ContainersThe Hacker News·Aug 7, 11:10 UTC · Aug 7, 2026Exploit / PoC in the wildCVE-2026-6456460
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux HostsThe Hacker News·Aug 6, 17:58 UTC · Aug 6, 2026Exploit / PoC in the wildCVE-2026-64561CVE-2026-53359CVE-2026-4631660
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsThe Hacker News·Jul 31, 11:17 UTC · Jul 31, 2026Exploit / PoC in the wildCVE-2026-66066CVE-2025-24293160
Researcher Says AI Helped Develop Linux TrafficThe Hacker News·Jul 28, 08:04 UTC · Jul 28, 2026Exploit / PoC in the wildCVE-2026-5326460
Public PoC Released for Critical libssh2 CVE-2026-55200 ClientThe Hacker News·Jun 29, 07:06 UTC · Jun 29, 2026Exploit / PoC in the wildCVE-2026-55200CVE-2019-3855CVE-2026-55199+1 CVEs160
Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, OpenThe Hacker News·Jun 9, 11:59 UTC · Jun 9, 2026Exploit / PoC in the wildCVE-2026-39987CVE-2026-31431CVE-2026-43284+1 CVEs160
DirtyDecrypt: PoC Released for yet another Linux flawSecurity Affairs·May 20, 07:36 UTC · May 20, 2026Exploit / PoC in the wildCVE-2026-31635CVE-2026-31431CVE-2026-43284+4 CVEs60
Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major DistributionsThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-31431CVE-2022-27666CVE-2026-43284+1 CVEs60
New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache CorruptionThe Hacker News·May 15, 00:00 UTC · May 15, 2026Exploit / PoC in the wildCVE-2026-4630060
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network PlatformsThe Hacker News·Feb 11, 13:28 UTC · Feb 11, 2026Exploit / PoC in the wildCVE-2026-0488CVE-2026-0509CVE-2025-32007+4 CVEs60
U.S. CISA adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 27, 14:54 UTC · Jan 27, 2026Exploit / PoC in the wildCVE-2018-14634CVE-2025-52691CVE-2026-21509+2 CVEs60
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs60
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel ZeroThe Hacker News·Nov 12, 11:14 UTC · Nov 12, 2025Exploit / PoC in the wildCVE-2025-62215CVE-2025-60724CVE-2025-62220+1 CVEs60
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever ShippedThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Exploit / PoC in the wildCVE-2025-24990CVE-2025-59230CVE-2025-47827+5 CVEs160
Meta warns of actively exploited flaw in FreeType librarySecurity Affairs·Mar 13, 11:02 UTC · Mar 13, 2025Exploit / PoC in the wildCVE-2025-2736360
3 Actively Exploited Zero-Day Flaws Patched in Microsoft's Latest Security UpdateThe Hacker News·Jan 21, 15:30 UTC · Jan 21, 2025Exploit / PoC in the wildCVE-2024-7344CVE-2025-21333CVE-2025-21334+13 CVEs60
Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler BugsThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2024Exploit / PoC in the wildCVE-2024-43451CVE-2024-49039CVE-2024-21410+6 CVEs60
Microsoft Issues Security Update Fixing 118 Flaws, Two Actively Exploited in the WildThe Hacker News·Oct 9, 12:48 UTC · Oct 9, 2024Exploit / PoC in the wildCVE-2024-43572CVE-2024-43573CVE-2024-43583+7 CVEs60
Critical Ghostscript flaw exploited in the wild. Patch it now!Security Affairs·Jul 8, 18:12 UTC · Jul 8, 2024Exploit / PoC in the wildCVE-2024-29510CVE-2024-29509CVE-2024-29506+3 CVEs60
Google "confirms" that exploited Chrome zero-day is actually in libwebp (CVE-2023-5129)Help Net Security·Sep 29, 10:48 UTC · Sep 29, 2023Exploit / PoC in the wildCVE-2023-5129CVE-2023-4863CVE-2023-4106460
Chrome zero-day exploited in the wild, patch now! (CVE-2023-4863)Help Net Security·Sep 29, 08:22 UTC · Sep 29, 2023Exploit / PoC in the wildCVE-2023-4863CVE-2023-41064CVE-2023-41061+1 CVEs60
Incomplete disclosures by Apple and Google create “huge blindspot” for 0Ars Technica · Security·Sep 21, 22:19 UTC · Sep 21, 2023Exploit / PoC in the wildCVE-2023-41064CVE-2023-486360
Microsoft Releases Fix for Zero-Day Flaw in July 2022 Security Patch RolloutThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2022Exploit / PoC in the wildCVE-2022-22047CVE-2022-22026CVE-2022-22049+14 CVEs60
Microsoft Releases Fix for New ZeroThe Hacker News·May 11, 16:06 UTC · May 11, 2022Exploit / PoC in the wildCVE-2022-26925CVE-2022-29972CVE-2022-22713+14 CVEs60
Critical PPP Daemon Flaw Opens Most Linux Systems to Remote HackersThe Hacker News·Mar 6, 14:17 UTC · Mar 6, 2020Exploit / PoC in the wildCVE-2020-859760
A new critical flaw in Exim exposes email servers to remote attacksSecurity Affairs·Sep 30, 14:40 UTC · Sep 30, 2019Exploit / PoC in the wildCVE-2019-16928CVE-2019-15846CVE-2019-1014960
Critical Flaws in Ghostscript Could Leave Many Systems at Risk of HackingThe Hacker News·Aug 22, 08:27 UTC · Aug 22, 2018Exploit / PoC in the wildCVE-2017-829160
Dirty COW Linux kernel zero-day exploited in the wild is now patchedHelp Net Security·Oct 24, 02:10 UTC · Oct 24, 2016Exploit / PoC in the wildCVE-2016-519560