See what became
exploitable.

Latest CVEs, exploit intelligence and public PoC references, updated hourly.

Browse latest
Last sync 22:05 UTC 8 of 8 sources healthy

Latest intelligence

61–75 of 412 matching entries · 2884 total · live data

CVEVulnerabilityCVSSUpdatedProductPoCKEV
CVE-2026-49975http2-bomb exploit7.514 Sep 202618:31 UTCUnknown productSee original advisory17 sourcesCandidateNoCVE-2026-49176CVE-2026-49176_LPE_POC exploit7.814 Sep 202618:31 UTCUnknown productSee original advisory17 sourcesCandidateNoCVE-2026-49069WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)0.020 Aug 202622:00 UTCUnknown productSee original advisory187 sourcesVerifiedNoCVE-2026-48909Joomla Extension 4.1.4 - PHP Object injection0.011 Aug 202622:00 UTCUnknown productSee original advisory3 sourcesVerifiedNoCVE-2026-48611Exploit for nns-ctf-php-is-my-passion CVE-2026-486119.811 Sep 202617:29 UTCUnknown productSee original advisory42 sourcesCandidateNoCVE-2026-46333CVE-2026-46333 exploit7.87 Sep 202619:19 UTCUnknown productSee original advisory34 sourcesCandidateNoCVE-2026-44706CVE-2026-44706 exploit8.514 Sep 202604:52 UTCUnknown productSee original advisory23 sourcesCandidateNoCVE-2026-44578Exploit for nextjs-cve-2026-44578 CVE-2026-445788.62 Sep 202612:19 UTCUnknown productSee original advisory65 sourcesCandidateNoCVE-2026-42978Exploit for Use After Free in Microsoft10.011 Sep 202622:10 UTCUnknown productSee original advisory158 sourcesVerifiedNoCVE-2026-42977Exploit for CVE-2026-42978-PoC-Research7.85 Sep 202613:44 UTCUnknown productSee original advisory33 sourcesCandidateNoCVE-2026-42533nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.0.026 Aug 202613:19 UTCUnknown productSee original advisory907 sourcesVerifiedNoCVE-2026-42167CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE0.024 Aug 202622:00 UTCUnknown productSee original advisory431 sourcesVerifiedNoCVE-2026-41456Bludit CMS 3.20.0 - Reflected Cross-Site Scripting0.01 Sep 202622:00 UTCUnknown productSee original advisory98 sourcesVerifiedNoCVE-2026-41096Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-210.011 Sep 202622:10 UTCUnknown productSee original advisory85 sourcesVerifiedNoCVE-2026-41089Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-210.011 Sep 202622:10 UTCUnknown productSee original advisory357 sourcesVerifiedNo

Signals, not noise.

Every item keeps its source trail. Confidence describes evidence quality; severity describes potential impact. They remain separate throughout the product.

01

Collect

Incremental source connectors preserve timestamps, URLs, and content hashes.

02

Correlate

CVE, GHSA, product, repository, and advisory identifiers are deduplicated.

03

Verify

Source quality, consistency, and independent references form the confidence score.

Get the signal.

Save your watch preferences in this browser. Email delivery is not connected.