See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 22:05 UTC 8 of 8 sources healthy

Latest intelligence

2806–2820 of 3062 matching entries · 3062 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2022-30190KEVMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability9.325 Aug 202602:55 UTCWindowsSee original advisory122 sourcesCandidateYesCVE-2022-29900Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified lfence mitigation.0.010 Sep 202622:00 UTCUnknown productSee original advisory26 sourcesCandidateNoCVE-2022-29567vaadin vulnerability5.714 Sep 202615:17 UTCvaadin14.8.5 through 14.8.9 (maven); 22.0.6 through 22.0.14 (maven); 23.0.0.beta2 through 23.0.8 (maven); 23.1.0.alpha1 through before 23.1.0.beta1 (maven)4 sourcesNoneNoCVE-2022-28368Dompdf 1.2.1 - Remote Code Execution (RCE)9.813 Sep 202618:32 UTCUnknown productSee original advisory45 sourcesVerifiedNoCVE-2022-26923KEVMicrosoft Active Directory Domain Services Privilege Escalation Vulnerability9.012 Sep 202615:06 UTCActive DirectorySee original advisory145 sourcesCandidateYesCVE-2022-26134KEVAtlassian Confluence Server and Data Center Remote Code Execution Vulnerability9.85 Sep 202612:45 UTCConfluence Server/Data CenterSee original advisory1957 sourcesVerifiedYesCVE-2022-25765pdfkit <0.8.6 command injection shell. The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. (Tested on ver 0.8.6) - CVE-2022-257650.01 Sep 202622:00 UTCUnknown productSee original advisory141 sourcesCandidateNoCVE-2022-24958n/a vulnerability7.811 Sep 202614:17 UTCn/an/a14 sourcesNoneNoCVE-2022-24715Icinga Web 2.10 - Authenticated Remote Code Execution8.88 Sep 202601:15 UTCUnknown productSee original advisory139 sourcesVerifiedNoCVE-2022-24637Open Web Analytics 1.7.3 - Remote Code Execution0.09 Sep 202622:00 UTCUnknown productSee original advisory252 sourcesVerifiedNoCVE-2022-24521KEVMicrosoft Windows CLFS Driver Privilege Escalation Vulnerability7.825 Aug 202613:38 UTCWindowsSee original advisory106 sourcesCandidateYesCVE-2022-24481Exploit for CVE-2022-24481-POC CVE-2022-24481 CVE-2022-245217.825 Aug 202613:38 UTCUnknown productSee original advisory71 sourcesCandidateNoCVE-2022-23773CVE-2022-23773-Reproduce exploit7.55 Sep 202612:41 UTCUnknown productSee original advisory46 sourcesCandidateNoCVE-2022-22972Exploit for CVE-2022-229729.85 Sep 202602:43 UTCUnknown productSee original advisory21 sourcesCandidateNoCVE-2022-22965KEVSpring Framework JDK 9+ Remote Code Execution Vulnerability9.828 Aug 202619:19 UTCSpring FrameworkSee original advisory100 sourcesCandidateYes

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.