Zimbra urges customers to manually fix actively exploited zeroSecurity Affairs·Jul 13, 20:12 UTC · Jul 13, 2023Exploit / PoC in the wildCVE-2022-41352CVE-2022-27925160
0patch releases unofficial patches for 3 Windows flaws yet to be fixedSecurity Affairs·Jan 23, 06:30 UTC · Jan 23, 2019Vulnerability55
SandboxEscaper expert is back and disclosed a new Windows ZeroSecurity Affairs·Oct 24, 14:53 UTC · Oct 24, 2018Exploit / PoC60
At least 1,300 Harbor cloud registry installs open to attackSecurity Affairs·Sep 19, 15:56 UTC · Sep 19, 2019Exploit / PoCCVE-2019-1609760
U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 20, 14:17 UTC · Mar 20, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2025-30066CVE-2024-5559160
Attackers exploit a new zeroSecurity Affairs·Feb 11, 23:06 UTC · Feb 11, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2024-55591160
China-linked hackers exploited Dell zero-day since 2024 (CVE-2026-22769)Help Net Security·Feb 18, 00:00 UTC · Feb 18, 2026Exploit / PoCCVE-2026-2276960
September 2025 CVE LandscapeRecorded Future·Oct 17, 00:00 UTC · Oct 17, 2025Exploit / PoC in the wildCVE-2025-53690CVE-2021-21311CVE-2025-20333+6 CVEs60
Attackers exploit Fortinet flaws to deploy Qilin ransomwareSecurity Affairs·Jun 6, 22:09 UTC · Jun 6, 2025Ransomware in the wildCVE-2024-21762CVE-2024-55591CVE-2025-2447260
Experts published PoC for Arcserve UDP auth bypass issueSecurity Affairs·Jun 29, 07:31 UTC · Jun 29, 2023Exploit / PoCCVE-2023-2625860
Critical SmarterMail Vulnerability Under Attack, No CVE YetSecurity Affairs·Jan 22, 15:14 UTC · Jan 22, 2026Vulnerability in the wild60
Over 200 PrestaShop stores expose installer, allowing full takeoverSansec (Magento / e-commerce security)·Apr 14, 13:40 UTC · Apr 14, 2026Vulnerability in the wildCVE-2026-7565060
Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245)Help Net Security·Jun 24, 15:41 UTC · Jun 24, 2026VulnerabilityCVE-2026-20245CVE-2026-20182CVE-2026-2012760
The Added Dangers Privileged Accounts Pose to Your Active DirectoryThe Hacker News·May 26, 10:49 UTC · May 26, 2022Industry55
Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin AccountsThe Hacker News·Nov 17, 14:23 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-6444660
Cisco fixed maximum severity flaw CVE-2026Security Affairs·May 21, 13:22 UTC · May 21, 2026Vulnerability in the wildCVE-2026-2022360
Flaws in Social Warfare plugin actively exploited in the wildSecurity Affairs·Apr 25, 18:35 UTC · Apr 25, 2019Exploit / PoC in the wildCVE-2019-997860
U.S. CISA adds Fortinet FortiOS flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 17, 14:29 UTC · Jan 17, 2025Exploit / PoC in the wildCVE-2024-55591CVE-2025-21333CVE-2025-21334+1 CVEs60
Hackers Actively Exploiting WidelyThe Hacker News·Apr 23, 19:23 UTC · Apr 23, 2019Exploit / PoC in the wildCVE-2019-997860
Easily exploitable RCE in Oracle WebLogic Server under attack (CVE-2020-14882)Help Net Security·Nov 3, 08:52 UTC · Nov 3, 2020VulnerabilityCVE-2020-14882CVE-2020-1475060
A flaw in outdated versions of Beaver Builder and Elementor plugins allows hacking WordPress sitesSecurity Affairs·Dec 13, 12:50 UTC · Dec 13, 2019Vulnerability55
King Addons flaw lets anyone become WordPress adminSecurity Affairs·Dec 3, 22:28 UTC · Dec 3, 2025Vulnerability in the wildCVE-2025-848960
Flaw in Ad Inserter WordPress plugin allows attackers to execute codeSecurity Affairs·Jul 15, 20:30 UTC · Jul 15, 2019Vulnerability55
Windows 11 to Deprecate NTLM, Add AI-Powered App Controls and Security DefensesThe Hacker News·Jun 6, 09:16 UTC · Jun 6, 2024Exploit / PoC60
Critical WordPress Modular DS Plugin Flaw Actively Exploited to Gain Admin AccessThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC in the wildCVE-2026-2355060
MAGENTO 2.0.16 and 2.1.9 security update fixes critical flaw in the platformSecurity Affairs·Apr 1, 21:06 UTC · Apr 1, 2018Vulnerability55
Google WordPress Site Kit plugin grants attacker Search Console AccessSecurity Affairs·May 14, 10:20 UTC · May 14, 2020Vulnerability55
Fortinet Warns of New Zero-Day Used in Attacks on Firewalls with Exposed InterfacesThe Hacker News·Jan 28, 13:09 UTC · Jan 28, 2025Exploit / PoC in the wildCVE-2024-5559160
Is it OK to publish PoC exploits for vulnerabilities and patches?Help Net Security·Apr 26, 10:40 UTC · Apr 26, 2023Exploit / PoC60
Experts warn of attacks exploiting WordPress gift card pluginSecurity Affairs·Dec 25, 19:42 UTC · Dec 25, 2022VulnerabilityCVE-2022-4535960
Fortinet fixes FortiOS zero-day exploited by attackers for months (CVE-2024-55591)Help Net Security·Jan 17, 09:05 UTC · Jan 17, 2025Exploit / PoC in the wildCVE-2024-5559160
Cisco fixed four critical flaws in Identity Services and WebexSecurity Affairs·Apr 16, 19:19 UTC · Apr 16, 2026Vulnerability in the wildCVE-2026-20184CVE-2026-20147CVE-2026-20180+1 CVEs60
Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet AttacksThe Hacker News·Dec 8, 09:15 UTC · Dec 8, 2025Exploit / PoC in the wildCVE-2025-6389CVE-2025-2611CVE-2025-161060
U.S. CISA adds Adminer, Cisco IOS, Fortra GoAnywhere MFT, Libraesva ESG, and Sudo flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 30, 09:07 UTC · Sep 30, 2025Exploit / PoC in the wildCVE-2021-21311CVE-2025-20352CVE-2025-10035+3 CVEs60
JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple StealersThe Hacker News·Dec 2, 05:40 UTC · Dec 2, 2025Malware55
Finding Azurescape – Cross-Account Container Takeover in Azure Container InstancesPalo Alto Unit 42·Jun 6, 01:32 UTC · Jun 6, 2024Exploit / PoC in the wildCVE-2019-5736CVE-2018-1002102160
Critical authentication bypass flaw in HPE Edgeline Infrastructure ManagerSecurity Affairs·May 5, 07:58 UTC · May 5, 2021VulnerabilityCVE-2021-2920360
Unpatched Wordpress Flaw Could Allow Hackers To Reset Admin PasswordThe Hacker News·May 4, 18:50 UTC · May 4, 2017VulnerabilityCVE-2017-829560