Skip to content
feed: live
>_0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2015-3246
[ HIGH ]CVSS 7.2EPSS 7.1%kev

Red Hat Libuser Race Condition Vulnerability

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

Red Hat / Libuser
CVE-2015-5287
[ MEDIUM ]CVSS 6.9EPSS 3.4%kev

Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Red Hat / Automatic Bug Reporting Tool
CVE-2019-1068
[ HIGH ]CVSS 8.8EPSS 44.7%kev

Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

Microsoft / SQL Server
CVE-2021-23758
[ HIGH ]CVSS 8.1EPSS 89.1%kev

Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Ajax.NET Professional / Ajax.NET Professional
CVE-2022-0995
[ HIGH ]CVSS 7.8EPSS 6.3%kev

Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.

Linux / Kernel
CVE-2026-8452
[ CRITICAL ]CVSS 9.8EPSS 1.0%kev

Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.

Citrix / NetScaler ADC and NetScaler Gateway
$ latest --more

From the desk

all articles →
~/articles/2026-08-26-anonymouskit-phaas-voice-ai-iphone-activation-lock
AnonyMousKIT: AI Voice Agents Phish iPhone Unlock Codes
mobile

AnonyMousKIT: AI Voice Agents Phish iPhone Unlock Codes

A new PhaaS platform, AnonyMousKIT, deploys AI voice agents to call iPhone owners and extract the codes needed to disable Activation Lock on stolen devices.

read →
~/articles/2026-08-26-nvidia-nemoclaw-ollama-webpage-llm-poisoning
NemoClaw Flaw Lets Webpages Poison Local AI Agents
ai tools

NemoClaw Flaw Lets Webpages Poison Local AI Agents

A networking flaw in NVIDIA NemoClaw lets malicious webpages hijack your local Ollama instance and plant hidden instructions in your AI agent.

read →
~/articles/2026-08-25-miniorange-saml-wordpress-auth-bypass-exploited
miniOrange SAML WordPress Flaws Under Active Exploit
● Breaking
wordpress

miniOrange SAML WordPress Flaws Under Active Exploit

Two authentication bypass flaws in the miniOrange SAML 2.0 SSO plugin are being actively exploited for WordPress admin takeover. Update immediately.

read →
~/articles/2026-08-25-zimbra-270-servers-breached-kev-deadline
270 Zimbra Servers Breached as KEV Deadline Expires
● Breaking
zimbra

270 Zimbra Servers Breached as KEV Deadline Expires

Attackers have compromised 270+ Zimbra ZCS servers via CVE-2026-73570 SNMP RCE. CISA's Aug 24 KEV patch deadline is past; upgrade to ZCS 10.1.20 now.

read →
~/articles/2026-08-25-oracle-weblogic-cve-2026-21962-kev
Oracle WebLogic CVE-2026-21962 Added to CISA KEV
● Breaking
oracle

Oracle WebLogic CVE-2026-21962 Added to CISA KEV

CISA added CVE-2026-21962 to KEV on August 25. CVSS 10.0. Unauthenticated HTTP access to Oracle WebLogic and HTTP Server. Active exploitation confirmed.

read →
~/articles/2026-08-25-what-is-epss-exploit-prediction-scoring-system
What Is EPSS? Exploit Prediction Scoring Explained
● Breaking
cisa kev

What Is EPSS? Exploit Prediction Scoring Explained

EPSS scores predict 30-day exploitation probability. A CVE with CVSS 6.5 and EPSS 0.94 deserves more urgency than a CVSS 9.8 with EPSS 0.01.

read →