See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 10:05 UTC 8 of 8 sources healthy

Latest intelligence

271–285 of 434 matching entries · 3145 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2022-41404Windows Apache Tomcat resource limits implementation guide for CVE-2022-41404 DoS vulnerability protection0.014 Sep 202622:00 UTCUnknown productSee original advisory8 sourcesCandidateNoCVE-2022-41401CVE-2022-41401 exploit6.511 Sep 202618:33 UTCUnknown productSee original advisory24 sourcesCandidateNoCVE-2022-37305rollback_car_attack_proverif exploit6.413 Sep 202618:09 UTCUnknown productSee original advisory16 sourcesCandidateNoCVE-2022-36945rollback_car_attack_proverif exploit6.413 Sep 202618:09 UTCUnknown productSee original advisory16 sourcesCandidateNoCVE-2022-34303CVE-2022-34303 - Secure Boot bypass via CryptoPro Secure Disk signed UEFI Shell (Shell_Full.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load unsigned UEFI applications.0.030 Aug 202622:00 UTCUnknown productSee original advisory25 sourcesCandidateNoCVE-2022-34302CVE-2022-34302 - Secure Boot bypass via New Horizon Datasys signed bootloader (shdloader.efi) - BYOVUA technique exploiting built-in custom PE/COFF loader to load unsigned UEFI applications without signature verification.0.06 Sep 202622:00 UTCUnknown productSee original advisory25 sourcesCandidateNoCVE-2022-34301CVE-2022-34301 - Secure Boot bypass via Eurosoft signed UEFI Shell (esdiags.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load unsigned UEFI applications.0.06 Sep 202622:00 UTCUnknown productSee original advisory26 sourcesCandidateNoCVE-2022-32073project_BIT_nmap_script exploit9.813 Sep 202618:28 UTCUnknown productSee original advisory16 sourcesCandidateNoCVE-2022-31101Prestashop blockwishlist module 2.1.0 - SQLi8.825 Aug 202621:54 UTCUnknown productSee original advisory136 sourcesVerifiedNoCVE-2022-30526CVE-2022-30526 exploit7.814 Sep 202604:52 UTCUnknown productSee original advisory31 sourcesCandidateNoCVE-2022-29900Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified lfence mitigation.0.010 Sep 202622:00 UTCUnknown productSee original advisory27 sourcesCandidateNoCVE-2022-28368Dompdf 1.2.1 - Remote Code Execution (RCE)9.813 Sep 202618:32 UTCUnknown productSee original advisory48 sourcesVerifiedNoCVE-2022-25765pdfkit <0.8.6 command injection shell. The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. (Tested on ver 0.8.6) - CVE-2022-257650.01 Sep 202622:00 UTCUnknown productSee original advisory151 sourcesCandidateNoCVE-2022-24715Icinga Web 2.10 - Authenticated Remote Code Execution8.88 Sep 202601:15 UTCUnknown productSee original advisory143 sourcesVerifiedNoCVE-2022-24637Open Web Analytics 1.7.3 - Remote Code Execution0.09 Sep 202622:00 UTCUnknown productSee original advisory261 sourcesVerifiedNo

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.