See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 22:05 UTC 8 of 8 sources healthy

Known exploited

16–30 of 213 matching entries · 2884 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2026-76460KEVCisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability0.015 Sep 202622:00 UTCIdentity Services EngineSee original advisory2 sourcesNoneYesCVE-2026-75650KEVAdobe Commerce vulnerability10.09 Sep 202603:18 UTCAdobe Commerce0 through 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug (custom); 0 through 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug (custom); 0 through 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug (custom)30 sourcesNoneYesCVE-2026-73570KEVZimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability0.026 Aug 202609:01 UTCZimbra Collaboration Suite (ZCS)See original advisory538 sourcesVerifiedYesCVE-2026-72898KEVMetabase SQL Injection Vulnerability0.010 Aug 202622:00 UTCMetabaseSee original advisory2 sourcesNoneYesCVE-2026-72530KEVTrueConf Server Code Injection Vulnerability0.019 Aug 202622:00 UTCServerSee original advisory86 sourcesVerifiedYesCVE-2026-72529KEVTrueConf Server Missing Authentication for Critical Function Vulnerability0.019 Aug 202622:00 UTCServerSee original advisory48 sourcesNoneYesCVE-2026-68820KEVMicrosoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability0.010 Aug 202622:00 UTCWindows Ancillary Function Driver for WinSockSee original advisory2 sourcesNoneYesCVE-2026-67277KEVRouterOS vulnerability8.811 Sep 202602:17 UTCRouterOS7.24 through before 7.24.2 (custom); 7.0.0 through before 7.23.4 (custom); 6.0.0 through before 6.49.21 (custom)30 sourcesNoneYesCVE-2026-66384KEVJFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability0.026 Aug 202622:00 UTCArtifactorySee original advisory49 sourcesNoneYesCVE-2026-65400KEVmacOS vulnerability9.815 Sep 202610:47 UTCmacOSbefore 14.8.9 (custom); before 15.7.9 (custom); before 26.6.1 (custom); before 26.7 (custom); before 27 (custom)44 sourcesCandidateYesCVE-2026-64849KEVMLflow Server-Side Request Forgery Vulnerability0.018 Aug 202622:00 UTCMLflowSee original advisory48 sourcesNoneYesCVE-2026-63077KEVJetBrains TeamCity Deserialization of Untrusted Data Vulnerability0.04 Aug 202622:00 UTCTeamCitySee original advisory2 sourcesNoneYesCVE-2026-63030KEVWordPress Core Interpretation Conflict Vulnerability0.026 Aug 202612:50 UTCCoreSee original advisory809 sourcesCandidateYesCVE-2026-60137KEVWordPress Core SQL Injection Vulnerability0.026 Aug 202612:50 UTCCoreSee original advisory809 sourcesCandidateYesCVE-2026-60004KEVGitea Code Injection Vulnerability0.026 Aug 202612:17 UTCGiteaSee original advisory809 sourcesCandidateYes

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.