See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 16:06 UTC 8 of 8 sources healthy

Latest intelligence

571–585 of 1050 matching entries · 3191 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2026-1122Exploit for CVE-2026-1122-IoT-Firmware-Update-Signature-Bypass-via-Low-Order-Point-Injection9.830 Aug 202618:58 UTCUnknown productSee original advisory85 sourcesCandidateNoCVE-2026-0770KEVLangflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability0.020 Jul 202622:00 UTCLangflowSee original advisory3 sourcesVerifiedYesCVE-2026-0740Ninja Forms Uploads - Unauthenticated PHP File Upload9.87 Sep 202619:21 UTCUnknown productSee original advisory114 sourcesVerifiedNoCVE-2026-0084Android vulnerability0.010 Sep 202602:17 UTCAndroid16-qpr2; 161 sourcesNoneNoCVE-2026-0073Exploit for CVE-2026-00738.827 Aug 202601:52 UTCUnknown productSee original advisory510 sourcesCandidateNoCVE-2026-0065Android vulnerability0.010 Sep 202602:17 UTCAndroid16-qpr2; 16; 15; 141 sourcesNoneNoCVE-2026-0013Exploit for PoC-in-GitHub CVE-2026-0009 CVE-2026-00138.46 Sep 202610:27 UTCUnknown productSee original advisory61 sourcesCandidateNoCVE-2026-0009Exploit for PoC-in-GitHub CVE-2026-0009 CVE-2026-00138.46 Sep 202610:27 UTCUnknown productSee original advisory61 sourcesCandidateNoCVE-2026-0001threat = { "id": "CVE-2026-0001", "title": "Apache HTTP Server Remote Code Execution", "vendor": "Apache", "product": "HTTP Server", "description": "A vulnerability in Apache HTTP Server allows remote attackers to execute arbitrary code.", "cvss": 9.8, "kev": True, "published": "2026-06-30" }0.04 Sep 202622:00 UTCUnknown productSee original advisory48 sourcesCandidateNoCVE-2025-71142Linux vulnerability5.514 Sep 202610:17 UTCLinux93f045741dac64facf90c2216f9a1d0876d122c4 through before 71953da7c979983917a4597bcad2c1ea6b8cc226 (git); f62a5d39368e34a966c8df63e1f05eed7fe9c5de through before 5d8b9d38a7676be7bb5e7d57f92156a98dab39fb (git); f62a5d39368e34a966c8df63e1f05eed7fe9c5de through before aa7d3a56a20f07978d9f401e13637a6479b13bd0 (git); 6.153 sourcesNoneNoCVE-2025-70336PodcastGenerator 3.2.9 - Stored XSS0.01 Sep 202622:00 UTCUnknown productSee original advisory108 sourcesVerifiedNoCVE-2025-69212CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing0.020 Aug 202622:00 UTCUnknown productSee original advisory196 sourcesCandidateNoCVE-2025-68686KEVFortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability0.026 Jul 202622:00 UTCFortiOSSee original advisory2 sourcesNoneYesCVE-2025-68137EVerest 2025.9.0 - DoS0.01 Sep 202622:00 UTCUnknown productSee original advisory191 sourcesVerifiedNoCVE-2025-66516Exploit for CVE-2025-66516-POC9.87 Sep 202619:12 UTCUnknown productSee original advisory35 sourcesCandidateNo

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.