CVEs
47,640
Known exploited
1,734
Breaches
1,020
Updated
1 hour ago

Security threats, piped to your terminal.

Spydr watches the CVE feeds, CISA’s known-exploited list and breach disclosures. Ask it from any terminal with curl, wire it into CI and alerts — or read the week’s highlights in The Security Skim.

curl -L spydr.io
Exploited this week
curl -L "spydr.io/threats?exploited=1&since=7d&limit=5"
spydr · threats · exploited · since 7d            2 results · synced 20:48 UTC
──────────────────────────────────────────────────────────────────────────────
 8.7 high      CVE-2026-88779   2026-10-04  KEV EPSS 0.59%  NetScaler ADC
               Vulnerability in NetScaler ADC and NetScaler Gateway. This iss…
 9.8 critical  CVE-2026-104286  2026-10-01  KEV  EPSS 2.2%  Fortinet FortiMail
               An improper limitation of a pathname to a restricted directory…
──────────────────────────────────────────────────────────────────────────────
page 1 of 1 · web: https://spydr.io/threats?exploited=1&since=7d&limit=5
covers: CVEs published since 2026-06-09 (the last 120 days), plus every CVE in CISA KEV
scripts: add &format=json (or ndjson, csv, rss) · help: curl -L spydr.io/help
Data: This product uses data from the NVD API but is not endorsed or certified by the NVD. CISA KEV · FIRST EPSS.
Your stack
curl -L "spydr.io/threats?q=nginx,openssl,linux&cvss=7&limit=5"
spydr · threats · q=nginx,openssl,linux · cvss ≥ 7 3452 results · synced 20:48 UTC
note: 2341 more CVEs match but have no score yet, so cvss=/severity= left them out. Add unscored=1 to include them.
──────────────────────────────────────────────────────────────────────────────
 9.2 critical  CVE-2026-42530   2026-06-17       EPSS 1.1%  F5 NGINX Open Sou…
               NGINX Open Source has a vulnerability in the ngx_http_v3_modul…
 9.2 critical  CVE-2026-42055   2026-06-17       EPSS 6.5%  F5 NGINX Open Sou…
               NGINX Plus and NGINX Open Source have a vulnerability in the n…
 7.1 high      CVE-2026-102335  2026-09-28      EPSS 0.23%  NginxProxyManager…
               Nginx Proxy Manager through 2.16.0 fails to restrict the advan…
 9.1 critical  CVE-2026-102334  2026-09-28      EPSS 0.45%  NginxProxyManager…
               Nginx Proxy Manager through 2.16.0 lacks rate-limiting on auth…
 8.8 high      CVE-2026-60005   2026-07-15      EPSS 0.53%  F5 NGINX Plus
               NGINX Plus and NGINX Open Source have a vulnerability in the n…
──────────────────────────────────────────────────────────────────────────────
page 1 of 691 · web: https://spydr.io/threats?q=nginx%2Copenssl%2Clinux&cvss=7&limit=5 · next: &page=2
covers: CVEs published since 2026-06-09 (the last 120 days), plus every CVE in CISA KEV
scripts: add &format=json (or ndjson, csv, rss) · help: curl -L spydr.io/help
Data: This product uses data from the NVD API but is not endorsed or certified by the NVD. CISA KEV · FIRST EPSS.
Breaches
curl -L "spydr.io/breaches?since=30d&limit=4"
spydr · breaches · since 30d                      7 results · synced 18:47 UTC
──────────────────────────────────────────────────────────────────────────────
2026-10-07  Double Counter            275K accounts     doublec…
            Email addresses, Geographic locations, Names, Usernames
2026-10-07  Angel One                 6.8M accounts     angelon…
            Bank account numbers, Dates of birth, Email addresses, Financial…
2026-09-30  Medela                    424K accounts     medela.… (sensitive)
            Email addresses, Employers, Job titles, Names, Phone numbers, Phy…
2026-09-22  LimeLeads                 17.8M accounts    limelea…
            Email addresses, Employers, Geographic locations, Job titles, Pho…
──────────────────────────────────────────────────────────────────────────────
page 1 of 2 · web: https://spydr.io/breaches?since=30d&limit=4
Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0.

Level B1 · The base

Two ways to keep up

The same feed, raw or distilled. Use whichever fits the moment.

Room 01 · Terminal

In your terminal

Every page on this site is also an API. Filter by keyword, CVE, CVSS score, exploit status or date, and get a table, JSON, CSV or RSS back.

  • curl -L "spydr.io/threats?q=nginx&cvss=7"
  • curl -L "spydr.io/threats?kev=1&since=7d"
  • curl -L "spydr.io/breaches?since=30d"
API & automation docs →

Room 02 · Mailroom

In your inbox

The Security Skim reads the feed for you: every Tuesday, the vulnerabilities being exploited, the breaches worth knowing about and what to patch first.

  • Weekly digest, five minutes to read
  • Long reads when something big breaks
  • No sponsors, unsubscribe from any issue
Read The Skim →

Level B2 · Bedrock

Latest

Straight from the feed. CVE data 1 hour ago, breaches 3 hours ago.

Open the full feed

Added to CISA’s exploited list · last 7 days

Vulnerabilities added to CISA KEV in the last 7 days
Score CVE Affected Added to KEV
8.7 high CVE-2026-88779 KEV NetScaler ADC 4 Oct 2026
9.4 critical CVE-2026-102490 KEV Zammad GmbH Zammad 2 Oct 2026
9.4 critical CVE-2026-102489 KEV Zammad GmbH Zammad 2 Oct 2026
9.8 critical CVE-2026-104286 KEV Fortinet FortiMail 1 Oct 2026
9.8 critical CVE-2026-76504 KEV Cisco Catalyst SD-WAN Manager 30 Sept 2026

New high and critical CVEs · last 24 hours

High and critical CVEs published in the last 24 hours
Score CVE Affected Published
10.0 critical CVE-2026-76482 Cisco License On-Prem 7 Oct 2026
10.0 critical CVE-2025-70518 7 Oct 2026
10.0 critical CVE-2026-102255 SonicWall SMA1000 7 Oct 2026
9.8 critical CVE-2026-95606 Liquid Web / StellarWP The Events Calendar 7 Oct 2026
9.8 critical CVE-2026-76501 Cisco NX-OS Software 7 Oct 2026
9.8 critical CVE-2026-76500 Cisco Application Policy Infrastructure Controller (APIC) 7 Oct 2026

Automate it

Plain HTTP, stable URLs and exit codes you can script against. Three places to start:

Alert Slack when something you run is exploited

crontab · hourly
0 * * * *  curl -s "https://spydr.io/threats.json?q=nginx,postgres,openssl&exploited=1&since=1h" \
  | jq -r '.results[] | "*\(.id)* \(.severity) — \(.products[0] // "")\n\(.url)"' \
  | while read -r line; do
      curl -s -X POST -H 'content-type: application/json' \
        -d "$(jq -n --arg t "$line" '{text:$t}')" "$SLACK_WEBHOOK_URL"
    done

Fail a build when a critical CVE lands in your stack

.github/workflows/security.yml
- name: Spydr gate
  run: |
    code=$(curl -s -o hits.txt -w '%{http_code}' \
      "https://spydr.io/threats?q=django,celery,redis&cvss=9&since=1d&fail=1")
    case $code in
      200) echo "No new critical CVEs" ;;
      409) cat hits.txt; exit 1 ;;
      *)   echo "Spydr unavailable ($code)"; exit 2 ;;
    esac

Follow it in any feed reader

RSS
https://spydr.io/threats.rss?exploited=1
https://spydr.io/threats.rss?q=kubernetes&cvss=7
https://spydr.io/breaches.rss
The Security Skim

The week in security, in five minutes.

A short email every Tuesday: what’s being exploited, which breaches matter, and the one thing to patch before Friday. Written by people, not scraped.

Subscribe

Free. Hosted on Substack at securityskim.com.