Feed updates every 3 hours
Vulnerabilities being exploited in the wild against the software people actually run on a server. We publish what is affected and the exact version that fixes it — never how to exploit it.
Unauthenticated SQL injection in Sangoma Switchvox allows remote code execution; confirmed exploited in the wild, no patch yet — restrict network access now.
Zimbra Collaboration Suite has a confirmed exploited command injection flaw in its SMTP handling, allowing unauthenticated code execution. Patch to 10.1.20 now.
Gitea has a critical code injection flaw, confirmed exploited, letting attackers with repo write access run commands as the service account. Patch to 1.27.1 now.
There were more than 40,000 CVEs published last year. Almost none of them matter to someone running a Linux server, and a feed that repeats all of them is noise. We publish a vulnerability only when it clears a gate that runs on every ingest:
Every version number on this site is looked up from OSV.dev and the GitHub Advisory Database, then rendered from that record — never written as prose. A wrong upgrade command in a security advisory is worse than no advisory at all, so the remediation table and the article text come from different places by design. Where no fixed version has been published yet, we say so rather than guessing.
No exploit code, no proof-of-concept, and no detail sufficient to reproduce an attack. We describe where a flaw lives, because that is what lets you judge your own exposure, and we stop there. Our readers are the people patching these systems, not the people scanning for them.
Vulnerability data from the CISA Known Exploited Vulnerabilities catalogue (CC0), the CVE Program (© MITRE, used under the CVE Terms of Use), EPSS by FIRST, OSV.dev (CC BY 4.0) and the GitHub Advisory Database (CC BY 4.0). This product uses the NVD API but is not endorsed or certified by the NVD.