See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 22:05 UTC 8 of 8 sources healthy

Latest intelligence

1–15 of 412 matching entries · 2884 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2026-91998CVE-2026-91998 exploit9.915 Sep 202611:35 UTCUnknown productSee original advisory17 sourcesCandidateNoCVE-2026-91995CVE-2026-91995 exploit9.315 Sep 202611:35 UTCUnknown productSee original advisory17 sourcesCandidateNoCVE-2026-89606CVE-2026-89606 exploit0.011 Sep 202619:45 UTCUnknown productSee original advisory41 sourcesCandidateNoCVE-2026-89308CVE-2026-89308 exploit9.315 Sep 202611:44 UTCUnknown productSee original advisory17 sourcesCandidateNoCVE-2026-89013Exploit for CVE-2026-890138.711 Sep 202620:07 UTCUnknown productSee original advisory45 sourcesVerifiedNoCVE-2026-89012Exploit for CVE-2026-890127.111 Sep 202620:05 UTCUnknown productSee original advisory45 sourcesVerifiedNoCVE-2026-86304MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding:...0.06 Sep 202621:17 UTCUnknown productbefore 0.006 (custom)3 sourcesNoneNoCVE-2026-86287Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths.0.07 Sep 202619:17 UTCUnknown productbefore 1.12 (custom)3 sourcesNoneNoCVE-2026-86219Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step.0.06 Sep 202616:17 UTCUnknown productbefore 2.2100 (custom)6 sourcesNoneNoCVE-2026-81861Exploit for CVE-2026-818610.011 Sep 202600:22 UTCUnknown productSee original advisory53 sourcesCandidateNoCVE-2026-80428CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22_ 10.0 < 10.10_ 11.0 < 11.3 - RCE0.010 Sep 202622:00 UTCUnknown productSee original advisory38 sourcesVerifiedNoCVE-2026-80099Exploit for CVE-2026-800998.812 Sep 202609:42 UTCUnknown productSee original advisory35 sourcesVerifiedNoCVE-2026-78804Exploit for CVE-2026-788046.010 Sep 202612:10 UTCUnknown productSee original advisory61 sourcesVerifiedNoCVE-2026-77771Exploit for CVE-2026-777717.512 Sep 202609:28 UTCUnknown productSee original advisory35 sourcesCandidateNoCVE-2026-76904PostGIS SQL Injection GeoTools0.026 Aug 202610:47 UTCUnknown productSee original advisory191 sourcesCandidateNo

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.