[cyb]
dash
10.10.2026 · 10:13 UTC
live · 30 sources
new / 7d
6
with poc
7
overdue
7
epss > 50%
3
patch
13
newest first · then epss ↓
CVE-2015-3306
98%
KEV
PoC
ProFTPD Improper Access Control Vulnerability
0d
↗
CVE-2016-3081
94%
KEV
Apache Struts Command Injection Vulnerability
0d
↗
CVE-2015-5477
91%
KEV
PoC
ISC BIND Data Processing Errors Vulnerability
0d
↗
CVE-2021-3199
14%
KEV
ONLYOFFICE Docs Server Path Traversal Vulnerability
0d
↗
CVE-2023-22894
3%
KEV
PoC
Strapi Cleartext Storage of Sensitive Information Vulnerability
0d
↗
CVE-2026-104286
2%
KEV
Fortinet FortiMail Path Traversal Vulnerability
!
↗
CVE-2026-76504
1%
KEV
PoC
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
!
↗
CVE-2026-88772
1%
KEV
PoC
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
!
↗
CVE-2026-102489
1%
KEV
Zammad GmbH Zammad Session Fixation Vulnerability
!
↗
CVE-2026-86950
1%
KEV
PoC
Apple Multiple Products Out-of-Bounds Write Vulnerability
2d
↗
CVE-2026-88771
1%
KEV
PoC
Citrix NetScaler Improper Input Validation Vulnerability
!
↗
CVE-2026-88779
0%
KEV
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
!
↗
CVE-2026-102490
0%
KEV
Zammad GmbH Zammad Improper Privilege Management Vulnerability
!
↗
exploit
12
github · exploit-db
07:02
🔍 Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment.
★ 2
↗
04:23
FortiMail CVE-2026-104286 (CVSS 9.8) 점검·대응 도구 (버전 확인, IoC 점검, 완화·패치 체크리스트)
↗
07:24
🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.
★ 1
↗
07:18
🔍 Identify and understand the local privilege escalation vulnerability (CVE-2025-68921) in Nahimic audio software, impacting many gaming laptops.
↗
04:55
Zombify <= 1.7.7 Unauthenticated Arbitrary File Upload
↗
04:24
Proof-of-concept exploit for CVE-2026-1668.
★ 3
↗
02:45
RCE in Kerio Control 9.4.5 via unsigned firmware update.
↗
02:34
KyrieKlay/CVE-2026-37107
↗
00:00
[webapps] InvoicePlane 1.7.1 - RCE
↗
09:03
webserverdude/f5_CVE-2026-21589_mitigation
↗
08:38
CVE-2026-102428 PoC: OrdaSoft Joomla OS CCK (com_os_cck) <=8.3.15 unauth SQLi — order_field/order_direction ORDER BY injection on public listings. Check + mass exploit, POCBIT-102428-OK marker, CVSS 9.3. https://pocbit.org/pocs/cve-2026-102428
↗
08:25
CVE-2026-106445 — Handlebars 4.0.0–4.7.9 RCE via Function.prototype.constructor bypass (GHSA-p8wg-vrv2-v86f). PoCbit PoC + Docker lab (4.7.9), check/exploit HTTP client, GHSA template chain. Fixed 4.7.10. https://pocbit.org/pocs/cve-2026-106445
↗
tooling
3
nuclei · atomic · releases
16:32
carlospolop/PEASS-ng 20261009-7c7e2445
releases
↗
17:30
SpecterOps/BloodHound v9.8.0
releases
↗
19:08
BishopFox/sliver v1.7.8
releases
↗
advisories
16
cisa · zdi · vendors
12:14
[NEU] [UNGEPATCHT] [mittel] Keycloak: Mehrere Schwachstellen
BSI
↗
17:44
[0day-rubbish] StreamSets Transformer 3.17.0 auth-mode none fallback and un-sandboxed ScalaDTransform execution to container root (8.1 primary)
Full Disclosure
↗
17:44
[0day-rubbish] RCDevs WebADM 2.4.14 authenticated log viewer sid command injection to webadm uid 999 code execution (7.2)
Full Disclosure
↗
17:44
[0day-rubbish] Maian Cart 3.8 addBanners unrestricted banner upload to PHP webshell and administrator command execution (7.2 primary, PR:H)
Full Disclosure
↗
09:52
2026-015: Critical Vulnerability in Multiple Atlassian Products
CERT-EU
↗
12:14
[NEU] [mittel] Red Hat Enterprise Linux (sssd, tftp, ansible-collection-ansible-posix): Mehrere Schwachstellen
BSI
↗
05:00
ZDI-CAN-33446: Microsoft
ZDI Advisories
↗
00:08
3 Vulnerabilities in GNU Aspell before 0.60.8.3
oss-sec
↗
22:07
mutt 2.4.3 released, fixes CVE-2026-107570
oss-sec
↗
20:31
Unfixed vulnerabilities in Cyrus SASL
oss-sec
↗
12:14
[NEU] [mittel] Obsidian: Mehrere Schwachstellen
BSI
↗
00:00
Introducing AlertZero: Inbox zero for your alert queue
Elastic Sec Labs
↗
12:22
Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
CISA Alerts
↗
06:41
UAC-0277: ClickFix на скомпрометованих вебсайтах для поширення LUNEXSTEALER
CERT-UA
↗
02:01
Flare-On 12 – Task 8
hasherezade
↗
12:00
Impact of AI on cyber threat from now to 2027
NCSC-UK
↗