See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 10:05 UTC 8 of 8 sources healthy

Latest intelligence

1891–1905 of 3399 matching entries · 3399 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2026-42945NGINX Plus vulnerability9.210 Sep 202611:20 UTCNGINX PlusR36 through before R36 P4 (custom); R32 through before R32 P6 (custom); 0.6.27 through before 1.30.1 (semver)67 sourcesVerifiedNoCVE-2026-42897KEVMicrosoft Exchange Server Cross-Site Scripting Vulnerability8.115 Sep 202610:56 UTCMicrosoftSee original advisory46 sourcesCandidateYesCVE-2026-42795Gleam vulnerability5.17 Sep 202623:17 UTCGleam0.10.0-rc1 through before 1.17.0 (semver); c82a2d83bd0c06cafdc196820deb3f89a9b3ff7c through before 6435a5528b9ae0449e2f32be579641ec485f6866 (git); v0.10.0-rc1-elixir through before v1.17.0-elixir (other); v0.10.0-rc1-erlang through before v1.17.0-erlang (other); v0.10.0-rc1-node through before v1.17.0-node (other); v0.10.0-rc1-node-slim through before v1.17.0-node-slim (other); v0.10.0-rc1-elixir-slim through before v1.17.0-elixir-slim (other); v0.10.0-rc1-erlang-slim through before v1.17.0-erlang-slim (other); v0.10.0-rc1-erlang-alpine through before v1.17.0-erlang-alpine (other); v0.10.0-rc1-elixir-alpine through before v1.17.0-elixir-alpine (other); v0.10.0-rc1-node-alpine through before v1.17.0-node-alpine (other); v0.10.0-rc1-scratch through before v1.17.0-scratch (other)5 sourcesNoneNoCVE-2026-42790OTP vulnerability7.618 Sep 202611:18 UTCOTP1.4 through before * (otp); 19.3 through before * (otp); b0c245e8132bb13171e277b1af59c0cec00c9459 through before * (git)12 sourcesNoneNoCVE-2026-42789OTP vulnerability7.018 Sep 202611:18 UTCOTP0.22 through before * (otp); 17.0 through before * (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before * (git)11 sourcesNoneNoCVE-2026-42587netty vulnerability7.518 Sep 202611:18 UTCnetty>= 4.2.0.Alpha1, < 4.2.13.Final; < 4.1.133.Final28 sourcesVerifiedNoCVE-2026-42584netty vulnerability7.318 Sep 202611:18 UTCnetty>= 4.2.0.Alpha1, < 4.2.13.Final; < 4.1.133.Final25 sourcesVerifiedNoCVE-2026-42581netty vulnerability5.818 Sep 202611:18 UTCnetty>= 4.2.0.Alpha1, < 4.2.13.Final; < 4.1.133.Final25 sourcesVerifiedNoCVE-2026-42579netty vulnerability7.518 Sep 202611:18 UTCnetty>= 4.2.0.Alpha1, < 4.2.13.Final; < 4.1.133.Final22 sourcesVerifiedNoCVE-2026-42578netty vulnerability2.918 Sep 202611:18 UTCnetty>= 4.2.0.Alpha1, < 4.2.13.Final; < 4.1.133.Final25 sourcesVerifiedNoCVE-2026-42536Exploit for Classic Buffer Overflow in Apache Http_Server CVE-2026-425367.510 Sep 202611:20 UTCApache HTTP Server2.4.0 through 2.4.67 (semver)59 sourcesVerifiedNoCVE-2026-42533nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.0.026 Aug 202613:19 UTCUnknown productSee original advisory1059 sourcesVerifiedNoCVE-2026-42508golang.org/x/crypto/ssh/knownhosts vulnerability9.115 Sep 202610:17 UTCgolang.org/x/crypto/ssh/knownhostsbefore 0.52.0 (semver)49 sourcesNoneNoCVE-2026-42505crypto/tls vulnerability5.316 Sep 202618:14 UTCcrypto/tlsbefore 1.25.12 (semver); 1.26.0-0 through before 1.26.5 (semver); 1.27.0-0 through before 1.27.0-rc.2 (semver)4 sourcesNoneNoCVE-2026-42503golang.org/x/tools/gopls vulnerability8.818 Sep 202613:16 UTCgolang.org/x/tools/gopls0.0.0 through before 0.22.0 (semver)2 sourcesNoneNo

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.