Skip to main content
Threat level · live

Severe

Mass exploitation or critical 0-day in the wild. Treat as incident.
KEV adds 24h
3
Criticals 7d
714
711
New exploits 7d
644
IOCs 24h
6,222
1,861
Live updates10/10healthyall sources →
  • CISA KEV Catalog
    just now
  • NVD CVE 2.0
    just now
  • GitHub Security Advisories
    just now
  • OSV.dev
    31 m ago
  • Microsoft MSRC
    22 h ago
  • CISA ICS-CERT advisories
    just now
  • CISA Cybersecurity Advisories
    22 h ago
  • abuse.ch URLhaus
    just now
  • abuse.ch ThreatFox
    just now
  • Nuclei templates
    just now

Zero-day attacks · live

3 new actively-exploited vulns added to CISA KEV in the last 24h.

View zero-days →
Vulnerabilities · 30 d
1,000
of 9,468 total
News & research · 30 d
165
New IOCs · 30 d
1,000
of 42,626 total

Severity mix

1,000 CVEs · 30 d
  • critical0
  • high0
  • medium932
  • low68

Top malware families

16 families · 1,000 hits 24 h

High risk this week

critical or exploit-available · 7 dview all
CVE-2026-47938Critical· 10.03 h ago

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. S

CVE-2026-30141Critical· 9.83 h ago

An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF file.

CVE-2026-48303Critical· 10.04 h ago

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does no

CVE-2026-47928Critical· 9.64 h ago

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user in

CVE-2026-46155Critical· 9.14 h ago

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_ws

CVE-2026-46244Critical· 9.14 h ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header o

CVE-2026-11638Critical· 9.65 h ago

Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-45447Critical· 9.85 h ago

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote

Trending IOCs

last 24 hoursview all
urlhttp://3659b.win/lottery.htmlopenphish
urlhttp://www.89240.xyz/openphish
urlhttp://combscustoms.com/instert/login.inopenphish
urlhttp://www.84123.xyz/openphish
urlhttp://bafkreiciaij2qznniztu7ofqnyoatv7tuuonnqbdm3v76jiqz3x2jhifka.ipfs.dweb.link/openphish
urlhttps://bafkreibeyykwgcztu75t7jipqbjliizpkwlkpdaqarxgmph35coirknoxu.ipfs.dweb.link/openphish
urlhttps://sp10ct6-dranex-biz-frurnik-platem.pages.dev/openphish
urlhttps://ecoviasemfila.guiasindividuais.online/ecovias/?xp&#61openphish
urlhttps://www.stainedconcretefloorsbymichael.com/44dewp/bkd/openphish
urlhttps://instagram.sitaci.com/openphish