Exploit Security News

Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.

Once a vulnerability is disclosed, the risk changes sharply the moment working exploit code becomes public — turning a theoretical bug into something any attacker can weaponize. This feed tracks proof-of-concept releases, exploitation write-ups and additions to exploit frameworks as they appear. A published exploit is usually the signal that patching moves from "should" to "urgent".

Recent Exploit items

CVE-2026-86171 A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID lea…
@cveNotify · Sep 6, 2026
CVE-2026-86170 A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes…
@cveNotify · Sep 6, 2026
CVE-2026-86168 A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument…
@cveNotify · Sep 6, 2026
CVE-2026-86167 A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argum…
@cveNotify · Sep 6, 2026
CVE-2026-86166 A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a…
@cveNotify · Sep 6, 2026
CVE-2026-86165 A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/ur…
@cveNotify · Sep 6, 2026
CVE-2026-86164 A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument I…
@cveNotify · Sep 6, 2026
CVE-2026-86163 A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads…
@cveNotify · Sep 6, 2026
CVE-2026-2100 A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism…
@cveNotify · Sep 6, 2026
CVE-2025-49794 A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the schema elements. This flaw…
@cveNotify · Sep 6, 2026
CVE-2026-86218 N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. 🎖
@cveNotify · Sep 6, 2026
CVE-2026-86162 A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument…
@cveNotify · Sep 6, 2026
CVE-2026-86161 A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation…
@cveNotify · Sep 6, 2026
CVE-2026-86160 A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of t…
@cveNotify · Sep 6, 2026
CVE-2026-86159 A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql…
@cveNotify · Sep 6, 2026
CVE-2026-75816 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_up…
@cveNotify · Sep 6, 2026
CVE-2026-18056 The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the a…
@cveNotify · Sep 6, 2026
CVE-2026-86152 A flaw has been found in Tenda CP3 27.5.57.101 . The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a…
@cveNotify · Sep 6, 2026
CVE-2026-4878 A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with wr…
@cveNotify · Sep 6, 2026
CVE-2025-1244 A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is…
@cveNotify · Sep 6, 2026
CVE-2026-86151 A vulnerability was detected in Tenda CP3 27.5.57.101 . The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Perf…
@cveNotify · Sep 6, 2026
CVE-2026-86150 A security vulnerability has been detected in Tenda CP3 27.5.57.101 . Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphra…
@cveNotify · Sep 5, 2026
CVE-2026-86149 A weakness has been identified in Tenda CP3 27.5.57.101 . This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/h…
@cveNotify · Sep 5, 2026
CVE-2026-86148 A security flaw has been discovered in Tenda CP3 27.5.57.101 . This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of th…
@cveNotify · Sep 5, 2026
CVE-2026-86060 RouterOS contains an argument-handling flaw in the SSH loginpath involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed,…
@cveNotify · Sep 5, 2026
CVE-2026-86060 RouterOS contains an argument-handling flaw in the SSH loginpath involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed,…
@cveNotify · Sep 5, 2026
CVE-2026-86207 An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs 🎖
@cveNotify · Sep 5, 2026
CVE-2026-76827 A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is poss…
@cveNotify · Sep 5, 2026
CVE-2025-2786 A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows…
@cveNotify · Sep 5, 2026
CVE-2024-11831 A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScri…
@cveNotify · Sep 5, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.