Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

CVE

20 articles

Security Affairs CVE WordPress 1d ago

Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access

Hackers exploit CVE-2026-3300 in Everest Forms Pro to inject PHP via form fields, creating rogue admin accounts. 29,300 attempts blocked.

1 IOC

Security Affairs →

GBHackers CVE VMware 1d ago

Multiple VMware Stored XSS Flaw Enable Attackers to Inject Malicious Scripts

VMware has disclosed multiple high-severity stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation (VCF) Operations, potentially...

T1059 3 IOCs

GBHackers →

CISA Advisories CVE Check Point 1d ago

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42271 BerriAI...

T1059 2 IOCs

CISA Advisories →

Help Net Security CVE 1d ago

CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)

A vulnerability (CVE-2026-28318) that can be exploited to crash SolarWinds Serv-U file transfer servers is being leveraged by attackers in the wild, the US C...

1 IOC

Help Net Security →

Security Affairs CVE Amazon 1d ago

IoT Botnet C0XMO Adds Competitor-Killing Capability

C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoS attacks. In Mar...

T1498 1 IOC

Security Affairs →

Security Affairs CVE 3d ago

U.S. CISA adds SolarWinds Serv-U flaw to its Known Exploited Vulnerabilities catalog

U.S.

1 IOC

Security Affairs →

BleepingComputer CVE WordPress 3d ago

Critical Everest Forms Pro flaw exploited to take over WordPress sites

Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPres...

1 IOC

BleepingComputer →

GBHackers CVE Amazon 3d ago

Critical UniFi OS Auth Bypass Flaws Lead to Unauthenticated Root RCE

Ubiquiti has addressed three critical vulnerabilities within the UniFi OS Server that attackers can chain together to achieve unauthenticated remote code exe...

T1190 T1556 3 IOCs

GBHackers →

GBHackers CVE 3d ago

CISA Alerts on Actively Exploited SolarWinds Serv-U Denial-of-Service Flaw

The U.S.

1 IOC

GBHackers →

The Hacker News CVE 3d ago

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

The U.S.

1 IOC

The Hacker News →

The Hacker News CVE Cisco 3d ago

Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available

Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation. The vulnerability, tracked as CVE-2...

1 IOC

The Hacker News →

SC Media CVE 4d ago

Hackers actively exploit SolarWinds Serv-U flaw to crash servers, CISA warns

The vulnerability, tracked as CVE-2026-28318, is a denial-of-service flaw in SolarWinds Serv-U file transfer software.

1 IOC

SC Media →

Unit 42 CVE Palo Alto Networks 4d ago

Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257

We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 ...

1 IOC

Unit 42 →

Security Affairs CVE Cisco 4d ago

Cisco SD-WAN Has a New Root-Level Problem, and There’s No Fix Yet

Cisco warns of CVE-2026-20245 in SD-WAN Manager, a flaw that can lead to root access via file upload command injection; no patch or workaround yet. Cisco war...

T1059 T1548 1 IOC

Security Affairs →

CISA Advisories CVE 4d ago

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-28318 SolarWind...

1 IOC

CISA Advisories →

GBHackers CVE 4d ago

Hugging Face Transformers Security Flaw Allows Remote Code Execution

A critical security flaw in Hugging Face Transformers, tracked as CVE-2026-4372, has exposed millions of machine learning workflows to silent remote code exe...

T1190 1 IOC

GBHackers →

GBHackers CVE Linux 4d ago

New Gafgyt Variant Targets Linux Systems With Modular Spread Tactics

A new Gafgyt-family botnet, tracked as C0XMO, marks a notable technical shift in IoT malware design: the separation of scanning and propagation into distinct...

1 IOC

GBHackers →

Help Net Security CVE Cisco 4d ago

Cisco SD-WAN 0-day exploited, no patch available (CVE-2026-20245)

A 0-day privilege escalation vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager that has yet to be patched by Cisco is being leveraged by attack...

T1548 3 IOCs

Help Net Security →

The Hacker News CVE WordPress 4d ago

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arb...

T1190 1 IOC

The Hacker News →

GBHackers CVE Linux 4d ago

CISA Issues Alert on Actively Exploited Linux Kernel Security Flaw

The U.S.

1 IOC

GBHackers →

«Previous page 1 2 3 4 5 ... 28 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA