WS_FTP flaw CVE-2023Security Affairs·Oct 2, 18:48 UTC · Oct 2, 2023Exploit / PoC in the wildCVE-2023-4004460
Palo Alto Networks warns that CVE-2025-0111 flaw is actively exploited in attacksSecurity Affairs·Feb 20, 06:32 UTC · Feb 20, 2025Vulnerability in the wildCVE-2025-0111CVE-2025-0108CVE-2024-947460
U.S. CISA adds SonicWall SonicOS and Palo Alto PAN-OS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 19, 22:32 UTC · Feb 19, 2025Exploit / PoC in the wildCVE-2025-0108CVE-2024-5370460
Attackers exploit recently disclosed Palo Alto Networks PANSecurity Affairs·Feb 15, 15:27 UTC · Feb 15, 2025Exploit / PoC in the wildCVE-2025-010860
CISA adds flaw in Citrix ShareFile to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 18, 17:45 UTC · Aug 18, 2023Exploit / PoC in the wildCVE-2023-2448960
Critical React2Shell Vulnerability Under Active Exploitation by Chinese Threat ActorsRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Vulnerability in the wildCVE-2025-5518260
Critical ServiceNow vulnerabilities being targeted by hackers, cyber agency warnsThe Record·Jul 30, 16:17 UTC · Jul 30, 2024Vulnerability in the wildCVE-2024-4879CVE-2024-5178CVE-2024-521760
Progress Software Releases Urgent Hotfixes for Multiple Security Flaws in WS_FTP ServerThe Hacker News·Oct 9, 06:43 UTC · Oct 9, 2023Ransomware in the wildCVE-2023-40044CVE-2023-42657CVE-2023-40045+5 CVEs60
They’ve begun: Attacks exploiting vulnerability with maximum 10 severity ratingArs Technica · Security·Oct 3, 21:53 UTC · Oct 3, 2023Vulnerability in the wildCVE-2023-40044CVE-2023-4265760
Hackers seen exploiting bugs in browsers and popular file transfer toolThe Record·Oct 3, 13:21 UTC · Oct 3, 2023Ransomware in the wildCVE-2023-5217CVE-2023-4004460
Citrix ShareFile vulnerability actively exploited (CVE-2023-24489)Help Net Security·Aug 17, 00:00 UTC · Aug 17, 2023Vulnerability in the wildCVE-2023-2448960
Two new high severity WordPress vulnerabilities, patch immediately!Help Net Security·Jul 21, 09:06 UTC · Jul 21, 2026Vulnerability in the wildCVE-2026-60137CVE-2026-63030160
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run CodeThe Hacker News·Jul 18, 05:23 UTC · Jul 18, 2026Exploit / PoC in the wildCVE-2026-63030CVE-2026-6013760
CosmicSting attack & defense overviewSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Data breach in the wildCVE-2024-2961CVE-2024-3410260
SessionReaper attacks have started, 3 in 5 stores still vulnerableSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Exploit / PoC in the wildCVE-2025-54236CVE-2026-7565060
SessionReaper, unauthenticated RCE in Magento & Adobe Commerce (CVE-2025Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2025-54236260
WebRTC Skimmer Bypasses CSP to Steal Payment Data from EThe Hacker News·Mar 26, 15:39 UTC · Mar 26, 2026Data breach in the wild60
Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992)Help Net Security·Mar 23, 00:00 UTC · Mar 23, 2026Vulnerability in the wildCVE-2026-21992CVE-2025-6175760
Oracle fixes critical RCE flaw CVE-2026Security Affairs·Mar 22, 15:37 UTC · Mar 22, 2026Vulnerability in the wildCVE-2026-21992CVE-2025-6175760
U.S. CISA adds an Oracle Fusion Middleware flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 22, 10:34 UTC · Nov 22, 2025Exploit / PoC in the wildCVE-2025-6175760
Attackers are chaining flaws to breach Palo Alto Networks firewallsHelp Net Security·Apr 18, 10:11 UTC · Apr 18, 2025Exploit / PoC in the wildCVE-2025-0108CVE-2024-9474CVE-2025-0111+1 CVEs60
Hackers Chain Exploits of Three Palo Alto Networks Firewall FlawsInfosecurity Magazine·Feb 20, 12:45 UTC · Feb 20, 2025Ransomware in the wildCVE-2025-0108CVE-2025-0111CVE-2024-947460
Researchers Reveal ConfusedFunction Vulnerability in Google Cloud PlatformThe Hacker News·Jul 29, 03:44 UTC · Jul 29, 2024Vulnerability in the wildCVE-2024-4879CVE-2024-5178CVE-2024-521760
Cisco Warns of Critical Flaw Affecting OnThe Hacker News·Jul 18, 13:13 UTC · Jul 18, 2024Exploit / PoC in the wildCVE-2024-20419CVE-2024-20401CVE-2024-34102+2 CVEs60
Ivanti Vulnerability Exploited to Install 'DSLog' Backdoor on 670+ IT InfrastructuresThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Vulnerability in the wildCVE-2024-21893CVE-2024-2188860
U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM VulnerabilityThe Hacker News·Jan 20, 04:42 UTC · Jan 20, 2024Vulnerability in the wildCVE-2023-35082CVE-2023-35078CVE-2023-35081+2 CVEs60
Cyber experts and officials raise alarms about exploits against Citrix and Apache productsThe Record·Nov 3, 18:13 UTC · Nov 3, 2023Ransomware in the wildCVE-2023-46604CVE-2023-496660
Citrix Bleed: Mass exploitation in progress (CVE-2023-4966)Help Net Security·Nov 2, 14:31 UTC · Nov 2, 2023Vulnerability in the wildCVE-2023-496660
Alert: PoC Exploits Released for Citrix and VMware VulnerabilitiesThe Hacker News·Nov 2, 12:20 UTC · Nov 2, 2023Exploit / PoC in the wildCVE-2023-34051CVE-2023-4966CVE-2023-35182+2 CVEs60
Citrix NetScaler bug exploited in the wild since August (CVE-2023-4966)Help Net Security·Oct 30, 09:56 UTC · Oct 30, 2023Exploit / PoC in the wildCVE-2023-4966CVE-2023-351960
CISA Adds Citrix ShareFile Flaw to KEV Catalog Due to In-theThe Hacker News·Aug 21, 03:43 UTC · Aug 21, 2023Exploit / PoC in the wildCVE-2023-24489CVE-2023-351960
Major Security Flaw Discovered in Metabase BI SoftwareThe Hacker News·Jul 28, 05:46 UTC · Jul 28, 2023Exploit / PoC in the wildCVE-2023-3864660
New Vulnerability in Popular WordPress Plugin Exposes Over 2 Million Sites to CyberattacksThe Hacker News·May 15, 00:00 UTC · May 15, 2023Vulnerability in the wildCVE-2023-30777CVE-2023-30177CVE-2023-31144+1 CVEs60
Popular IBM file transfer tool vulnerable to cyberattacks, CISA saysThe Record·Mar 8, 08:21 UTC · Mar 8, 2023Ransomware in the wildCVE-2022-4798660
U.S. Cybersecurity Agency CISA Adds Three New Vulnerabilities in KEV CatalogThe Hacker News·Feb 22, 12:38 UTC · Feb 22, 2023Exploit / PoC in the wildCVE-2022-47986CVE-2022-41223CVE-2022-40765+3 CVEs60
CISA adds IBM Aspera Faspex and Mitel MiVoice to Known Exploited Vulnerabilities CatalogSecurity Affairs·Feb 22, 12:00 UTC · Feb 22, 2023Exploit / PoC in the wildCVE-2022-47986CVE-2022-41223CVE-2022-4076560