See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 04:05 UTC 8 of 8 sources healthy

Latest intelligence

2056–2070 of 3315 matching entries · 3315 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2026-25550BarTender 2010 vulnerability9.316 Sep 202614:17 UTCBarTender 20100 through 10.1 R4 (custom); 0 through R9 (custom); 0 through R10 (custom)4 sourcesNoneNoCVE-2026-25544Payload CMS 3.72.0 - Blind SQL Injection0.031 Aug 202622:00 UTCUnknown productSee original advisory110 sourcesVerifiedNoCVE-2026-25470ACPT (Pro) - Custom Post Types Plugin for WordPress vulnerability10.014 Sep 202613:17 UTCACPT (Pro) - Custom Post Types Plugin for WordPressn/a through before 2.0.52 (custom)1 sourcesNoneNoCVE-2026-25253Exploit for Gideon CVE-2024-218879.15 Sep 202609:04 UTCUnknown productSee original advisory41 sourcesCandidateNoCVE-2026-25157Exploit for Gideon CVE-2024-218879.15 Sep 202609:04 UTCUnknown productSee original advisory41 sourcesCandidateNoCVE-2026-24842node-tar vulnerability8.27 Sep 202611:18 UTCnode-tar< 7.5.752 sourcesVerifiedNoCVE-2026-24763Exploit for Gideon CVE-2024-218879.15 Sep 202609:04 UTCUnknown productSee original advisory41 sourcesCandidateNoCVE-2026-24708Nova vulnerability8.211 Sep 202611:17 UTCNovabefore 30.2.2 (semver); 31.0.0 through before 31.2.1 (semver); 32.0.0 through before 32.1.1 (semver)9 sourcesNoneNoCVE-2026-24332WebSocket API service vulnerability4.312 Sep 202622:17 UTCWebSocket API service0 through 2026-01-16 (custom)1 sourcesNoneNoCVE-2026-24291Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV10.011 Sep 202622:10 UTCUnknown productSee original advisory137 sourcesVerifiedNoCVE-2026-24110KEVWindows print service boundary error7.81 Sep 202608:31 UTCWindows Print ServiceServer 2022–20258 sourcesNoneYesCVE-2026-24061KEVGNU InetUtils Argument Injection Vulnerability9.826 Aug 202610:23 UTCInetUtilsSee original advisory2278 sourcesVerifiedYesCVE-2026-24049wheel vulnerability7.110 Sep 202611:17 UTCwheel>= 0.40.0, < 0.46.282 sourcesVerifiedNoCVE-2026-23980Exploit for CVE-2026-23980 — Authenticated error-based SQL injection in Apache Superset < 6.0.0 via sqlExpression bypass0.012 Sep 202622:00 UTCUnknown productSee original advisory41 sourcesCandidateNoCVE-2026-23940hexpm vulnerability7.18 Sep 202612:17 UTChexpmbefore 2026-03-10 (date); 82911daf5f8fb2ab44f298e3ba22b90bc1ae3746 through before 495f01607d3eae4aed7ad09b2f54f31ec7a7df01 (git)5 sourcesNoneNo

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.