Skip to content
THREATWIRE

Tracker

Exploit Radar

PoC, exploit, and active exploitation are separate statuses. If it is not confirmed, the record says Unknown or No PoC.

Filters match the recorded status. Active exploitation is not implied by a proof of concept.

HighActive ExploitationKEV0-day

CVE-2026-88779

NetScaler SAML memory overflow

DoS

Published 2d ago

CriticalNo PoC

CVE-2026-59265

OpenOffice Java document code execution

RCE

Published 3d ago

CriticalPoC Available

CVE-2026-94545

Satori SVG injection affecting Next.js ImageResponse

RCE

Published 6d ago

CriticalNo PoC

CVE-2026-96760

Authlib JSON signature list treated as verified

Auth bypass

Published 7d ago

CriticalActive ExploitationKEV0-day

CVE-2026-88771

NetScaler unauthenticated command execution

RCE

Published 8d ago

HighNo PoC

CVE-2026-96748

PyMongo connection-string host injection

Other

Published 11d ago

HighNo PoC

CVE-2026-96746

MongoDB C driver connection-monitor overflow

DoS

Published 11d ago

HighPoC Available

CVE-2026-15742

PostgreSQL fuzzystrmatch integer wraparound

RCE

Published 13 Aug 2026

CriticalActive ExploitationKEV

CVE-2026-60004

Gitea diffpatch Git hook code execution

RCE

Published 27 Jul 2026

HighPoC Available

CVE-2026-48842

Roundcube virtuser_query SQL injection

SQLi

Published 25 May 2026

CriticalPoC Available

CVE-2026-40281

Gotenberg ExifTool argument injection

Other

Published 6 May 2026

CriticalNo PoC

CVE-2026-27962

Authlib accepts a key embedded in the token

Auth bypass

Published 16 Mar 2026

HighNo PoC

CVE-2026-28802

Authlib none algorithm accepted on 1.6.5 and 1.6.6

Auth bypass

Published 6 Mar 2026

CriticalActive ExploitationKEV0-day

CVE-2024-3400

PAN-OS GlobalProtect command injection

RCE

Published 12 Apr 2024

CriticalExploit Available

CVE-2024-3094

xz Utils supply-chain backdoor

Supply chain

Published 29 Mar 2024

CriticalActive ExploitationKEV

CVE-2021-44228

Apache Log4j JNDI remote code execution

RCE

Published 10 Dec 2021