Skip to main content
Threat level · live

Severe

Mass exploitation or critical 0-day in the wild. Treat as incident.
KEV adds 24h
1
Criticals 7d
744
696
New exploits 7d
652
IOCs 24h
5,480
3,525
Live updates10/10healthyall sources →
  • CISA KEV Catalog
    just now
  • NVD CVE 2.0
    just now
  • GitHub Security Advisories
    just now
  • OSV.dev
    25 m ago
  • Microsoft MSRC
    7 h ago
  • CISA ICS-CERT advisories
    25 m ago
  • CISA Cybersecurity Advisories
    7 h ago
  • abuse.ch URLhaus
    just now
  • abuse.ch ThreatFox
    just now
  • Nuclei templates
    25 m ago

Zero-day attacks · live

1 new actively-exploited vuln added to CISA KEV in the last 24h.

View zero-days →
Vulnerabilities · 30 d
1,000
of 11,496 total
News & research · 30 d
235
New IOCs · 30 d
1,000
of 53,937 total

Severity mix

1,000 CVEs · 30 d
  • critical0
  • high0
  • medium896
  • low104

Top malware families

12 families · 1,000 hits 24 h

High risk this week

critical or exploit-available · 7 dview all
CVE-2026-49973Critical· 9.4EPSS 0%7 h ago

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any n

CVE-2026-47131Critical· 10.0EPSS 0%7 h ago

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE E

CVE-2026-12027Critical· 9.6EPSS 0%10 h ago

Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severit

CVE-2026-53838Critical· 9.813 h ago

OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authori

CVE-2026-53609Critical· 9.113 h ago

ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary va

CVE-2026-53519Critical· 9.113 h ago

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the dashboard's NoRoute handler treats any URL whose raw string starts with /dashboard as an admi

CVE-2026-46716Critical· 9.9EPSS 0%13 h ago

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitr

CVE-2026-44990Critical· 9.3EPSS 0%14 h ago

Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

Trending IOCs

last 24 hoursview all
urlhttps://cannabis-dna.com/threatfox
urlhttp://89.46.38.100/c0b30d15260a4d8888dc.phpthreatfox
urlhttps://ctl.it-bd.com/threatfox
domainctl.it-bd.comthreatfox
domainglo.gadgetwalabd.comthreatfox
urlhttps://glo.gadgetwalabd.com/threatfox
urlhttps://arsimonopa.com/live/threatfox
urlhttps://stripplasst.com/live/threatfox
domaingor.emiraride.comthreatfox
urlhttps://gor.emiraride.com/threatfox