See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 22:05 UTC 8 of 8 sources healthy

Known exploited

31–45 of 208 matching entries · 3062 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2026-59822KEVBerriAI LiteLLM Improper Authentication Vulnerability0.01 Sep 202622:00 UTCLiteLLMSee original advisory53 sourcesNoneYesCVE-2026-59310KEVBroadcom VMware vCenter Path Traversal Vulnerability0.017 Aug 202622:00 UTCVMware vCenterSee original advisory2 sourcesNoneYesCVE-2026-58704KEVAndroid vulnerability8.817 Sep 202602:17 UTCAndroidAndroid kernel5 sourcesNoneYesCVE-2026-55040KEVMicrosoft SharePoint Weak Authentication Vulnerability0.026 Aug 202608:15 UTCSharePointSee original advisory431 sourcesVerifiedYesCVE-2026-53362KEVLinux Kernel Unspecified Vulnerability0.026 Aug 202622:00 UTCKernelSee original advisory102 sourcesCandidateYesCVE-2026-50522KEVMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability0.021 Jul 202622:00 UTCSharePointSee original advisory2 sourcesNoneYesCVE-2026-49869KEVKestra OSS OS Command Injection Vulnerability0.01 Sep 202622:00 UTCKestra OSSSee original advisory99 sourcesVerifiedYesCVE-2026-48907KEVWidget Factory Joomla Content Editor Improper Access Control Vulnerability0.026 Aug 202612:34 UTCJoomla Content EditorSee original advisory1262 sourcesVerifiedYesCVE-2026-48710KEVKludex Starlette HTTP Request/Response Smuggling Vulnerability0.01 Sep 202622:00 UTCStarletteSee original advisory288 sourcesVerifiedYesCVE-2026-45659KEVMicrosoft SharePoint Server Deserialization of Untrusted Data Vulnerability8.811 Sep 202613:02 UTCSharePoint ServerSee original advisory55 sourcesCandidateYesCVE-2026-42897KEVMicrosoft Exchange Server Cross-Site Scripting Vulnerability8.115 Sep 202610:56 UTCMicrosoftSee original advisory31 sourcesCandidateYesCVE-2026-42018KEVartifactory vulnerability7.512 Sep 202602:16 UTCartifactorybefore 7.111.20 (custom); 7.117.0 through before 7.117.27 (custom); 7.125.0 through before 7.125.19 (custom); 7.133.0 through before 7.133.28 (custom); 7.146.0 through before 7.146.8 (custom)25 sourcesNoneYesCVE-2026-42016KEVartifactory vulnerability8.112 Sep 202602:16 UTCartifactorybefore 7.133.11 (custom)25 sourcesNoneYesCVE-2026-41940KEVWebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability9.826 Aug 202610:03 UTCcPanel & WHM and WP2 (WordPress Squared)See original advisory1452 sourcesVerifiedYesCVE-2026-39987KEVMarimo Remote Code Execution Vulnerability0.01 Sep 202622:00 UTCMarimoSee original advisory105 sourcesVerifiedYes

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.