Global Network Activity Map
Real-time global network and scanning activity from open, public data sets. Updated periodically.
Sources: abuse.ch, SANS Internet Storm Center
i Real-time network and scanning activity indicators from open, public data sets. Last update: -
European vulnerability database (ENISA EUVD)
ENISA's EU vulnerability database - critical and actively used vulnerabilities from European sources (CIRCL, CERT-EU, etc.) is complemented by the possibility of using EPSS.
Source: ENISA EUVD
- CVE
- unique Vulnerabilities and Exposure.
- CWE
- vulnerability type classification: Common Weakness Enumeration.
- EPSS
- the estimated probability that vulnerability will be used in the next 30 days (Exploit Predication Scoring System).
Critical CVSS 9.0-10.0
Highest severity. Large potential effects - immediate updating is recommended, even without known use.
Tonec - Critical vulnerability
Kalkitech - Critical vulnerability
irontec - Critical vulnerability
StellarWP - Critical vulnerability
StellarWP - Critical vulnerability
Unknown - Critical vulnerability
Unknown - Critical vulnerability
Unknown - Critical vulnerability
GitLab - Critical vulnerability
GitLab - Critical vulnerability
prowler-cloud - Critical vulnerability
n/a - Critical vulnerability
themerex - Critical vulnerability
WPEverest - Critical vulnerability
WAVLINK Technology - Critical vulnerability
Assets used in real environment
Imperfections already used by attackers in real attacks (EUVD marked with date of use). Prevent priority regardless of CVSS.
GitLab - Critical vulnerability
Google - High risk vulnerability
ConnectWise - Critical vulnerability
Microsoft - High risk vulnerability
Microsoft - High risk vulnerability
Adobe - Critical vulnerability
N-Able - Critical vulnerability
MikroTik - Critical vulnerability
MikroTik - High risk vulnerability
MikroTik - Critical vulnerability
Google - High risk vulnerability
NetScaler - Critical vulnerability
JFrog - High risk vulnerability
Cisco - Medium risk vulnerability
JFrog - High risk vulnerability
i The list shall be updated periodically from the ENISA EUVD. The same CVE can also appear in the list of NSAs below - these are different sources.
Priority Anti-Risks (CISA KEV)
Imperfections listed by CISA as a priority in the avoidable catalogue. The federal authorities must eliminate them within a certain timeframe - good practice for others too. Updated periodically.
Source: CISA KEV katalogs
ConnectWise ScreenConnect - Incorrect management of privileges
JFrog Artifictory - Incorrect authorization
JFrog Artifictory - Incorrect authentication
GitLab Community Edition and Enterprise Edition - Actively used vulnerability
MikroTik RouterOS - Actively used vulnerability
MikroTik RouterOS - Missing authentication for critical function
Citrix NetSclarer - Circulation of authentication along the adjacent road
Fortinet Multiple Products - Dynamic memory overflow
Google Chromium V8 - Cross border recording in memory
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) - Circulation of authentication along the adjacent road
Microsoft Windows - Tracking the link without checking
N-able N-central - Actively used vulnerability
Adobe Commerce and Magento - Actively used vulnerability
Microsoft Windows - Dynamic memory overflow
Google Chromium V8 - Tips mismatch in resource handling
Kestra Kestra OSS - Injection of operating system commands
Berriai LiteLM - Incorrect authentication
Kludex Starlette - Inadequate processing of requests
JFrog Artifictory - Incorrect authentication
Sangoma Switchvox - SQL injection
i CISA KEV - catalogue of priority avoidable vulnerabilities The spoon in the CVE list below indicates overlap with the latest injuries.
Top 20 latest vulnerabilities
Published CVE vulnerabilities from public sources. The list contains only those that already know the manufacturer or the product - without it the record does not say what is directly vulnerable. Updated periodically.
DALIBO PostgreSQL Anonymizer < 3.1.4 - SQL injection
The database query is composed of unverified data that can allow you to read or change the contents of the database.
DALIBO PostgreSQL Anonymizer < 3.1.4 - SQL injection
The database query is composed of unverified data that can allow you to read or change the contents of the database.
MISP ≤ 2.5.45 - New vulnerability
Awaiting assessment of severity.
code-projects Hotel and Tourism Reservation in PHP 1.0 - Sensitive disclosures
The system shall disclose sensitive information to parties for whom it is not intended.
code-projects Hotel and Tourism Reservation in PHP 1.0 - Intersite scripting
The web page gets unverified content that can execute a foreign script and steal a session in the user browser.
Mstfakts College-Management-System - Medium risk vulnerability
Plan an update.
THU-MAIC OpenMAIC < 1.0.1 - Missing authentication for critical function
A critical function is available without authentication.
jupyter nbviewer ≤ 1.0.1 - Crossing the road
Insufficient file path check allows access to files outside the allowed folder.
Mstfakts College-Management-System - Incorrect authentication
Identity checks are insufficient to allow access without valid accreditation data.
Mstfakts College-Management-System - Lack of neutralisation of special symbols
Data are transferred to another system without separation from control symbols, so they can be interpreted as a command.
wger-project wger < 2.6 - Medium risk vulnerability
Plan an update.
wger-project wger < 2.6 - Medium risk vulnerability
Plan an update.
wger-project wger < 2.5 - Uncontrolled consumption of resources
Resource consumption is not limited, which may impair access to the service.
wger-project wger ≤ master - Missing authorization
The right of access is not verified which can allow access to foreign resources.
h3js h3 < 1.15.6 - Crossing the road
Insufficient file path check allows access to files outside the allowed folder.
h3js h3 < 1.15.9 - Lack of neutralisation of special symbols
Data are transferred to another system without separation from control symbols, so they can be interpreted as a command.
h3js h3 < 1.15.9 - Crossing the road
Insufficient file path check allows access to files outside the allowed folder.
h3js h3 < 2.0.1-rc.18 - Uncontrolled consumption of resources
Resource consumption is not limited, which may impair access to the service.
maximhq Bifrost < 2.0.0 - Involuntary code injection
Unverified data are interpreted as a program code that can change the application's performance.
Open5GS 2.7.7 Unjustified rights
The component is given more rights than it requires.
i The list is updated periodically from public CVE sources.
Top 20 technology news
Most popular news from global technology, security and software stories. Updated periodically.
Source: Hacker News
- 01
- 02
- 03
- 04
- 05
- 06
- 07
- 08
- 09
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
i The list is updated periodically from public sources of technology news.