CVE-2026-39987: Marimo RCE exploited in hours after disclosureSecurity Affairs·Apr 11, 09:44 UTC · Apr 11, 2026Vulnerability in the wildCVE-2026-39987CVE-2026-3301760
Cline Kanban Flaw Lets Websites Hijack AI Coding AgentsInfosecurity Magazine·May 7, 14:30 UTC · May 7, 2026Vulnerability55
Log4J Still Among Top Exploited Vulnerabilities, Cato FindsInfosecurity Magazine·May 7, 17:22 UTC · May 7, 2024VulnerabilityCVE-2021-44228CVE-2017-984160
Buffer overflow exposes unpatched Squid servers to RCE and DoS attacksSecurity Affairs·Aug 24, 08:28 UTC · Aug 24, 2019VulnerabilityCVE-2019-1252760
Critical remote code execution flaw affects older Diebold Nixdorf ATMsSecurity Affairs·Jun 9, 09:28 UTC · Jun 9, 2019Vulnerability55
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI MemoryThe Hacker News·Jul 29, 15:39 UTC · Jul 29, 2026VulnerabilityCVE-2026-59726160
Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code ExecutionThe Hacker News·Feb 18, 16:35 UTC · Feb 18, 2026VulnerabilityCVE-2026-232960
Cybercriminals Targeting Apache NiFi Instances for Cryptocurrency MiningThe Hacker News·May 31, 15:44 UTC · May 31, 2023VulnerabilityCVE-2020-14882CVE-2020-1488360
Zyxel CPE Devices Face Active Exploitation Due to Unpatched CVE-2024The Hacker News·Feb 5, 04:14 UTC · Feb 5, 2025Vulnerability in the wildCVE-2024-40891CVE-2024-40890CVE-2024-57726+3 CVEs60
SAP April 2018 Security Patch Day address critical flaws in web browser controls in SAP Business ClientSecurity Affairs·Apr 12, 06:14 UTC · Apr 12, 2018VulnerabilityCVE-2017-7668CVE-2018-2408CVE-2018-2409+8 CVEs60
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-ofThe Hacker News·Jul 2, 15:49 UTC · Jul 2, 2026Vulnerability in the wildCVE-2026-8451CVE-2026-8452CVE-2026-8655+4 CVEs60
Critical Remote Hacking Flaws Disclosed in Linphone and MicroSIP SoftphonesThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2021VulnerabilityCVE-2021-3305660
3 iOS 0-days, a cellular network compromise, and HTTP used to infect an iPhoneArs Technica · Security·Sep 23, 00:23 UTC · Sep 23, 2023VulnerabilityCVE-2023-41993CVE-2023-41991CVE-2023-41992+1 CVEs60
Biggest DDoSes of all time generated by protocol 0Ars Technica · Security·Oct 15, 00:00 UTC · Oct 15, 2023Vulnerability55
UPS: Observations on CVE-2015-3113, Prior ZeroPalo Alto Unit 42·Nov 1, 09:48 UTC · Nov 1, 2018VulnerabilityCVE-2015-3113CVE-2014-1776CVE-2014-633260
Magento wish list exploit bypasses WAF protectionSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026VulnerabilityCVE-2022-2408660
CitrixBleed 2:a nightmare that echoes CitrixBleed flaw in NetScalerSecurity Affairs·Jun 26, 07:31 UTC · Jun 26, 2025VulnerabilityCVE-2025-5777CVE-2023-4966CVE-2025-534960
Fuzzing µC/OS protocol stacks, Part 1: HTTP server fuzzingCisco Talos·Aug 28, 16:00 UTC · Aug 28, 2024Vulnerability55
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
Cinterion EHS5 3G UMTS/HSPA Module ResearchKaspersky Securelist·Jun 13, 10:00 UTC · Jun 13, 2024VulnerabilityCVE-2020-1585860