Skip to content
feed: live
0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2015-3306
[ CRITICAL ]CVSS 10.0EPSS 99.5%kev

ProFTPD Improper Access Control Vulnerability

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

ProFTPD / ProFTPD
CVE-2015-5477
[ HIGH ]CVSS 7.8EPSS 99.4%kev

ISC BIND Data Processing Errors Vulnerability

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.

ISC / BIND
CVE-2016-3081
[ HIGH ]CVSS 8.1EPSS 96.1%kev

Apache Struts Command Injection Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

Apache / Struts
CVE-2021-3199
[ CRITICAL ]CVSS 9.8EPSS 19.4%kev

ONLYOFFICE Docs Server Path Traversal Vulnerability

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

ONLYOFFICE / Docs
CVE-2023-22894
[ MEDIUM ]CVSS 4.9EPSS 3.6%kev

Strapi Cleartext Storage of Sensitive Information Vulnerability

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.

Strapi / Strapi
CVE-2026-88779
[ HIGH ]CVSS 7.5EPSS 0.6%kev

Citrix NetScaler Memory Buffer Flaw Enables Denial-of-Service Attacks

NetScaler ADC and Gateway contain an exploited memory-buffer flaw enabling denial of service. CISA KEV listed October 4, federal deadline October 7.

Citrix / NetScaler ADC, NetScaler Gateway
$ latest --more

Latest security news

all articles →
~/articles/2026-10-10-ahsaycbs-cve-2026-105134-unpatched-active-exploitation
cloud

AhsayCBS Backup Platform Exploited, No Patch Ready

Two AhsayCBS flaws, including a CVSS 10.0 auth bypass, are chained to drop webshells and XMRig miners on MSP networks. No patch is available.

read →
~/articles/2026-10-10-sonicwall-sma1000-cve-2026-102255-active-exploitation
sonicwall

SonicWall SMA1000 Max-Severity Flaw Exploited

CVE-2026-102255 (CVSS 10.0) in SonicWall SMA1000 hit active exploitation within 72 hours of the October 7 patch. Patch immediately; attribution not yet confirmed.

read →
~/articles/2026-10-10-cisa-kev-flax-typhoon-five-cves-oct11-deadline
● Breaking
cisa kev

CISA: Five Flax Typhoon CVEs Added, Feds Have Until Oct 11

CISA added five vulnerabilities tied to China's Flax Typhoon to its KEV catalog on Oct 8; federal agencies must patch or discontinue use by October 11.

read →
~/articles/2026-10-09-pwn2own-ireland-2026-final-98-zero-days
threat intel

Pwn2Own Ireland Closes: $1.26M for 98 Zero-Days

Pwn2Own Ireland 2026 wrapped with 98 unique zero-day vulnerabilities exploited and $1,262,000 in prizes paid out to competing security researchers.

read →
~/articles/2026-10-09-idcf-cloud-ransomware-japan-govt-outage
ransomware

IDCF Cloud Ransomware Hits Japanese Gov Clients

IDC Frontier confirmed a ransomware attack took down an IDCF Cloud data center cluster serving government and enterprise clients in Japan.

read →
~/articles/2026-10-09-citrix-netscaler-cve-2026-107406-rce-dos
citrix

Citrix NetScaler: Critical CVSS 9.5 RCE, Patch Now

CVE-2026-107406, CVSS 9.5, is a memory overflow in Citrix NetScaler that allows unauthenticated RCE or DoS in SAML-configured deployments. Patch now.

read →