See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 10:05 UTC 8 of 8 sources healthy

Latest intelligence

121–135 of 434 matching entries · 3145 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2026-3576Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF0.010 Aug 202622:00 UTCUnknown productSee original advisory2 sourcesVerifiedNoCVE-2026-1122Exploit for CVE-2026-1122-IoT-Firmware-Update-Signature-Bypass-via-Low-Order-Point-Injection9.830 Aug 202618:58 UTCUnknown productSee original advisory83 sourcesCandidateNoCVE-2026-0740Ninja Forms Uploads - Unauthenticated PHP File Upload9.87 Sep 202619:21 UTCUnknown productSee original advisory111 sourcesVerifiedNoCVE-2026-0073Exploit for CVE-2026-00738.827 Aug 202601:52 UTCUnknown productSee original advisory491 sourcesCandidateNoCVE-2026-0013Exploit for PoC-in-GitHub CVE-2026-0009 CVE-2026-00138.46 Sep 202610:27 UTCUnknown productSee original advisory59 sourcesCandidateNoCVE-2026-0009Exploit for PoC-in-GitHub CVE-2026-0009 CVE-2026-00138.46 Sep 202610:27 UTCUnknown productSee original advisory59 sourcesCandidateNoCVE-2026-0001threat = { "id": "CVE-2026-0001", "title": "Apache HTTP Server Remote Code Execution", "vendor": "Apache", "product": "HTTP Server", "description": "A vulnerability in Apache HTTP Server allows remote attackers to execute arbitrary code.", "cvss": 9.8, "kev": True, "published": "2026-06-30" }0.04 Sep 202622:00 UTCUnknown productSee original advisory47 sourcesCandidateNoCVE-2025-70336PodcastGenerator 3.2.9 - Stored XSS0.01 Sep 202622:00 UTCUnknown productSee original advisory106 sourcesVerifiedNoCVE-2025-69212CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing0.020 Aug 202622:00 UTCUnknown productSee original advisory183 sourcesCandidateNoCVE-2025-68137EVerest 2025.9.0 - DoS0.01 Sep 202622:00 UTCUnknown productSee original advisory187 sourcesVerifiedNoCVE-2025-66516Exploit for CVE-2025-66516-POC9.87 Sep 202619:12 UTCUnknown productSee original advisory33 sourcesCandidateNoCVE-2025-66478🔧 Fix vulnerable versions in Next.js and React RSC apps with one command to secure against CVE-2025-66478. Improve your app's safety effortlessly.10.029 Aug 202622:00 UTCUnknown productSee original advisory1232 sourcesCandidateNoCVE-2025-65856Exploit for CVE-2025-658569.828 Aug 202609:34 UTCUnknown productSee original advisory93 sourcesCandidateNoCVE-2025-65271CVE-2025-65271 exploit8.814 Sep 202604:52 UTCUnknown productSee original advisory31 sourcesCandidateNoCVE-2025-60689Linksys E1200_2.0.04 - Unauthenticated OS Command Injection0.030 Aug 202622:00 UTCUnknown productSee original advisory104 sourcesVerifiedNo

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.