Spydr watches the CVE feeds, CISA’s known-exploited list and breach disclosures. Ask it from any terminal with
curl, wire it into CI and alerts — or read the week’s highlights in The Security Skim.
46,280 CVEs1,734 known exploited1,018 breachesupdated 1 hour ago
Exploited this week
$ curl "https://spydr.io/threats?exploited=1&since=7d&limit=5"spydr · threats · exploited · since 7d5 results · synced 20:44 UTC────────────────────────────────────────────────────────────────────────────── 8.7 high CVE-2026-88779 2026-10-04 KEVEPSS 0.53% NetScaler ADC
Vulnerability in NetScaler ADC and NetScaler Gateway. This iss… 9.8 criticalCVE-2026-104286 2026-10-01 KEV EPSS 2.2% Fortinet FortiMail
An improper limitation of a pathname to a restricted directory… 9.4 criticalCVE-2026-102490 2026-09-30 KEVEPSS 0.63% Zammad GmbH Zammad
All versions of Zammad including the latest alpha enable the l… 9.4 criticalCVE-2026-102489 2026-09-30 KEV EPSS 1.4% Zammad GmbH Zammad
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack… 9.8 criticalCVE-2026-76504 2026-09-30 KEV EPSS 1.6% Cisco Catalyst SD…
A vulnerability in the API session-based authentication manage…──────────────────────────────────────────────────────────────────────────────page 1 of 1 · web: https://spydr.io/threats?exploited=1&since=7d&limit=5scripts: add &format=json (or ndjson, csv, rss) · help: curl https://spydr.io/helpData: This product uses data from the NVD API but is not endorsed or certified by the NVD. CISA KEV · FIRST EPSS.
Your stack
$ curl "https://spydr.io/threats?q=nginx,openssl,linux&cvss=7&limit=5"spydr · threats · q=nginx,openssl,linux · cvss ≥ 73394 results · synced 20:44 UTC────────────────────────────────────────────────────────────────────────────── 9.2 criticalCVE-2026-42530 2026-06-17 EPSS 1.1% F5 NGINX Open Sou…
NGINX Open Source has a vulnerability in the ngx_http_v3_modul… 9.2 criticalCVE-2026-42055 2026-06-17 EPSS 6.5% F5 NGINX Open Sou…
NGINX Plus and NGINX Open Source have a vulnerability in the n… 7.1 high CVE-2026-102335 2026-09-28 EPSS 0.23% NginxProxyManager…
Nginx Proxy Manager through 2.16.0 fails to restrict the advan… 9.1 criticalCVE-2026-102334 2026-09-28 EPSS 0.45% NginxProxyManager…
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on auth… 8.8 high CVE-2026-60005 2026-07-15 EPSS 0.53% F5 NGINX Plus
NGINX Plus and NGINX Open Source have a vulnerability in the n…──────────────────────────────────────────────────────────────────────────────page 1 of 679 · web: https://spydr.io/threats?q=nginx%2Copenssl%2Clinux&cvss=7&limit=5 · next: &page=2scripts: add &format=json (or ndjson, csv, rss) · help: curl https://spydr.io/helpData: This product uses data from the NVD API but is not endorsed or certified by the NVD. CISA KEV · FIRST EPSS.
Breaches
$ curl "https://spydr.io/breaches?since=30d&limit=4"spydr · breaches · since 30d5 results · synced 18:44 UTC──────────────────────────────────────────────────────────────────────────────
2026-09-30 Medela 424K accounts medela.… (sensitive)Email addresses, Employers, Job titles, Names, Phone numbers, Phy…
2026-09-22 LimeLeads 17.8M accounts limelea…Email addresses, Employers, Geographic locations, Job titles, Pho…
2026-09-21 Burger King Russia 3.2M accounts burgerk…Dates of birth, Email addresses, Genders, Geographic locations, N…
2026-09-13 Chess.com (2026) 4.7M accounts chess.c…Email addresses, Geographic locations, Names, Usernames──────────────────────────────────────────────────────────────────────────────page 1 of 2 · web: https://spydr.io/breaches?since=30d&limit=4Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0.
Two ways to keep up
The same feed, raw or distilled. Use whichever fits the moment.
In your terminal
Every page on this site is also an API. Filter by keyword, CVE, CVSS score, exploit status or date, and get a table, JSON, CSV or RSS back.
The Security Skim reads the feed for you: every Tuesday, the vulnerabilities being exploited, the breaches
worth knowing about and what to patch first.