See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 22:05 UTC 8 of 8 sources healthy

Latest intelligence

61–75 of 427 matching entries · 3062 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2026-50416Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-210.011 Sep 202622:10 UTCUnknown productSee original advisory97 sourcesVerifiedNoCVE-2026-49975http2-bomb exploit7.514 Sep 202618:31 UTCUnknown productSee original advisory23 sourcesCandidateNoCVE-2026-49176CVE-2026-49176_LPE_POC exploit7.814 Sep 202618:31 UTCUnknown productSee original advisory23 sourcesCandidateNoCVE-2026-49069WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)0.020 Aug 202622:00 UTCUnknown productSee original advisory199 sourcesVerifiedNoCVE-2026-48909Joomla Extension 4.1.4 - PHP Object injection0.011 Aug 202622:00 UTCUnknown productSee original advisory3 sourcesVerifiedNoCVE-2026-48611Exploit for nns-ctf-php-is-my-passion CVE-2026-486119.811 Sep 202617:29 UTCUnknown productSee original advisory48 sourcesCandidateNoCVE-2026-46333CVE-2026-46333 exploit7.87 Sep 202619:19 UTCUnknown productSee original advisory37 sourcesCandidateNoCVE-2026-44706CVE-2026-44706 exploit8.514 Sep 202604:52 UTCUnknown productSee original advisory29 sourcesCandidateNoCVE-2026-44578Exploit for nextjs-cve-2026-44578 CVE-2026-445788.62 Sep 202612:19 UTCUnknown productSee original advisory71 sourcesCandidateNoCVE-2026-42978Exploit for Use After Free in Microsoft10.011 Sep 202622:10 UTCUnknown productSee original advisory182 sourcesVerifiedNoCVE-2026-42977Exploit for CVE-2026-42978-PoC-Research7.85 Sep 202613:44 UTCUnknown productSee original advisory39 sourcesCandidateNoCVE-2026-42533nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.0.026 Aug 202613:19 UTCUnknown productSee original advisory964 sourcesVerifiedNoCVE-2026-42167CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE0.024 Aug 202622:00 UTCUnknown productSee original advisory461 sourcesVerifiedNoCVE-2026-41456Bludit CMS 3.20.0 - Reflected Cross-Site Scripting0.01 Sep 202622:00 UTCUnknown productSee original advisory104 sourcesVerifiedNoCVE-2026-41096Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-210.011 Sep 202622:10 UTCUnknown productSee original advisory97 sourcesVerifiedNo

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.