Skip to content
feed: live
0dayNews

0dayNews — Vulnerability & Exploit News

$ kev-tracker --recent

Known Exploited Vulnerabilities

full tracker →
CVE-2015-3306
[ CRITICAL ]CVSS 10.0EPSS 98.0%kev

ProFTPD Improper Access Control Vulnerability

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

ProFTPD / ProFTPD
CVE-2015-5477
[ HIGH ]CVSS 7.8EPSS 91.8%kev

ISC BIND Data Processing Errors Vulnerability

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.

ISC / BIND
CVE-2016-3081
[ HIGH ]CVSS 8.1EPSS 94.5%kev

Apache Struts Command Injection Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

Apache / Struts
CVE-2021-3199
[ CRITICAL ]CVSS 9.8EPSS 14.5%kev

ONLYOFFICE Docs Server Path Traversal Vulnerability

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

ONLYOFFICE / Docs
CVE-2023-22894
[ MEDIUM ]CVSS 4.9EPSS 3.4%kev

Strapi Cleartext Storage of Sensitive Information Vulnerability

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.

Strapi / Strapi
CVE-2026-88779
[ HIGH ]CVSS 7.5EPSS 0.6%kev

Citrix NetScaler Memory Buffer Flaw Enables Denial-of-Service Attacks

NetScaler ADC and Gateway contain an exploited memory-buffer flaw enabling denial of service. CISA KEV listed October 4, federal deadline October 7.

Citrix / NetScaler ADC, NetScaler Gateway
$ latest --more

Latest security news

all articles →
~/articles/2026-10-09-citrix-netscaler-cve-2026-107406-rce-dos
citrix

Citrix NetScaler: Critical CVSS 9.5 RCE, Patch Now

CVE-2026-107406, CVSS 9.5, is a memory overflow in Citrix NetScaler that allows unauthenticated RCE or DoS in SAML-configured deployments. Patch now.

read →
~/articles/2026-10-09-fbi-flax-typhoon-microscan-fishhub-domains
ics ot

FBI Seizes Domains for Flax Typhoon Breach Tools

The FBI seized seven domains used by Chinese state-sponsored Flax Typhoon to operate MicroScan and FishHub tools in critical infrastructure intrusions.

read →
~/articles/2026-10-09-cisco-nxos-five-critical-rce
● Breaking
cisco

Cisco Patches Five CVSS 9.8 Flaws in NX-OS

Cisco issued advisories for five critical NX-OS vulnerabilities, all CVSS 9.8, enabling unauthenticated remote code execution with root on Nexus data center switches.

read →
~/articles/2026-10-08-firefox-fake-crypto-wallet-extensions-16
browser

Fake Rabby, OKX Extensions Steal Recovery Phrases

Researchers found 16 malicious Firefox extensions posing as Rabby and OKX wallets, capable of extracting recovery phrases and private keys from cryptocurrency users.

read →
~/articles/2026-10-08-pwn2own-ireland-day2-45-zero-days
threat intel

Pwn2Own Ireland Day 2: 45 More Zero-Days, $232K

Day two at Pwn2Own Ireland 2026 added 45 zero-day vulnerabilities and $232,500 in prizes. Samsung Galaxy S26 fell three more times. Vendors have 90 days to patch.

read →
~/articles/2026-10-08-monstercloud-ceo-ransomware-fraud-charges
ransomware

MonsterCloud CEO Charged for Secret Ransom Scheme

Zohar Pinhasi charged with wire fraud after prosecutors allege he secretly paid ransomware operators while billing victims over $19 million for proprietary recovery services.

read →