Skip to content
feed: live
0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2015-3306
[ CRITICAL ]CVSS 10.0EPSS 96.8%kev

ProFTPD Improper Access Control Vulnerability

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

ProFTPD / ProFTPD
CVE-2015-5477
[ HIGH ]CVSS 7.8EPSS 91.3%kev

ISC BIND Data Processing Errors Vulnerability

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.

ISC / BIND
CVE-2016-3081
[ HIGH ]CVSS 8.1EPSS 93.4%kev

Apache Struts Command Injection Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

Apache / Struts
CVE-2021-3199
[ CRITICAL ]CVSS 9.8EPSS 8.2%kev

ONLYOFFICE Docs Server Path Traversal Vulnerability

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

ONLYOFFICE / Docs
CVE-2023-22894
[ MEDIUM ]CVSS 4.9EPSS 1.7%kev

Strapi Cleartext Storage of Sensitive Information Vulnerability

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.

Strapi / Strapi
CVE-2026-88779
[ HIGH ]CVSS 7.5EPSS 0.6%kev

Citrix NetScaler Memory Buffer Flaw Enables Denial-of-Service Attacks

NetScaler ADC and Gateway contain an exploited memory-buffer flaw enabling denial of service. CISA KEV listed October 4, federal deadline October 7.

Citrix / NetScaler ADC, NetScaler Gateway
$ latest --more

Latest security news

all articles →
~/articles/2026-10-08-monstercloud-ceo-ransomware-fraud-charges
● Breaking
ransomware

MonsterCloud CEO Charged for Secret Ransom Scheme

Zohar Pinhasi charged with wire fraud after prosecutors allege he secretly paid ransomware operators while billing victims over $19 million for proprietary recovery services.

read →
~/articles/2026-10-08-lmcache-cve-2026-105192-unpatched-rce
ai tools

Critical LMCache Flaw Exposes LLM Servers to Unauth RCE

CVE-2026-105192, a CVSS 9.8 flaw in LMCache's multiprocess server, lets unauthenticated attackers run code on LLM inference infrastructure. No patch exists.

read →
~/articles/2026-10-08-atlassian-cve-2026-21589-active-exploitation
● Breaking
atlassian

Atlassian CVE-2026-21589: Exploits Active, Patch Now

Active exploitation of CVE-2026-21589 began within hours of a public PoC. All eight affected Atlassian Data Center products need patching immediately.

read →
~/articles/2026-10-07-chrome-155-247-vulnerabilities-four-critical
browser

Chrome 155 Patches 4 Critical UAF Bugs, 247 Total

Google shipped Chrome 155 with 247 fixes, including four critical use-after-free bugs in core browser components. No active exploitation reported yet.

read →
~/articles/2026-10-07-cert-ua-lunexstealer-fake-cloudflare-clickfix
threat intel

CERT-UA: 100+ Sites Hijacked to Drop LunexStealer

Ukraine's CERT-UA tracked 100+ compromised sites serving LunexStealer through fake Cloudflare verification pages. Attributed to UAC-0277, observed September 2026.

read →
~/articles/2026-10-07-android-october-2026-25-vulnerabilities
google

Android October Patches Fix 25 Flaws, 7 Critical

Google's October 2026 Android update patches 25 vulnerabilities, including a critical System flaw that enables local privilege escalation without user interaction.

read →