RadicalNotion.AIRadicalNotion.AIRadicalNotion.AI

We do not sell or share your personal information

© 2026 RadicalNotion.AI

Security Data

  • CWE Directory
  • CAPEC Directory
  • CNA Directory
  • CNA Report Cards
  • Data Sources

Calculators

  • CVSS Calculator
  • CVSS 4.0
  • CVSS 3.1
  • CVSS 3.0
  • CVSS 2.0

Platform

  • My Vulnerabilities
  • Insights
  • Notifications
  • Account
  • Pricing

Learn

  • All guides
  • What is a CVE?
  • What is CVSS?
  • The CISA KEV catalog
  • What is EPSS?

Company

  • About us
  • Blog
  • Book a demo

Get Started

  • Sign up
  • Log in

Legal

  • Privacy
  • Terms
RadicalNotion.AIRadicalNotion.AI

Security data

  • Weaknesses (CWE)The MITRE CWE weakness catalog
  • Attack Patterns (CAPEC)MITRE CAPEC attack patterns
  • CNAsNumbering authorities + report cards
  • VendorsVulnerabilities by vendor

Tools

  • CVSS CalculatorScore CVSS 4.0, 3.1, 3.0 & 2.0

Resources

  • LearnPlain-English security guides
  • Data SourcesHow we source CVE data
About UsBlogPricingBook a Demo
Log in
  1. Home
  2. Blog

Blog

Log in
2008!

CVE-2008-0015: CISA Adds Actively Exploited Microsoft Video ActiveX Stack Overflow to KEV Catalog

CISA added CVE-2008-0015 to its Known Exploited Vulnerabilities catalog on February 17, 2026, confirming active exploitation of a critical stack-based buffer overflow in Microsoft's Video ActiveX control that allows complete system takeover via a malicious webpage.

Radical Notion Team4 months ago
Metro Development Server Vuln

Metro4Shell: React Native Dev Server Flaw Exploited in the Wild to Hijack Developer Machines

A trivially exploitable command-injection vulnerability in the React Native CLI's Metro development server is being actively exploited in the wild. CISA has added CVE-2025-11953 to its Known Exploited Vulnerabilities catalog — here's what every React Native team needs to know right now.

Radical Notion Team4 months ago
SSH

OpenSSH VerifyHostKeyDNS Bypass: Decade-Old Logic Flaw Enables Server Impersonation

A critical authentication bypass in OpenSSH (CVE-2025-26465) has lurked undetected since 2014, allowing attackers to impersonate any SSH server when a rarely-enabled option is configured. The vulnerability affects all releases from 6.8p1 through 9.9p1.

Radical Notion Team4 months ago
Blog post featured image 4

Windows DWM Zero-Day Exploited in the Wild to Bypass ASLR Protections

Microsoft patched CVE-2026-20805, a Desktop Window Manager information disclosure flaw actively exploited to defeat memory protections. CISA added it to the KEV catalog, requiring federal agencies to patch by February 3, 2026.

Radical Notion Team5 months ago
mogodb

MongoBleed: Critical Unauthenticated Memory Disclosure Hits MongoDB Server

A critical vulnerability dubbed 'MongoBleed' allows unauthenticated attackers to extract sensitive data from MongoDB server memory through malformed Zlib headers. CISA confirms active exploitation in the wild.

Radical Notion Team5 months ago
Blog post featured image 4

Unpatched DigiEver DVRs Under Active Attack by Mirai Botnets

A critical command injection flaw in DigiEver surveillance devices is being actively exploited by multiple botnets. The vendor has refused to patch, leaving thousands of devices permanently vulnerable.

Radical Notion Team5 months ago
Blog post featured image 1

React2Shell: Chinese APTs Exploit Critical React Server Components RCE

A maximum-severity (CVSS 10.0) vulnerability in React Server Components is being actively exploited by Chinese state-sponsored actors and ransomware groups. The flaw allows unauthenticated remote code execution on servers running default configurations of Next.js and other React frameworks.

Radical Notion Team6 months ago
Blog post featured image 5

CISA KEV: Kentico CMS Bug Gives Attackers Admin Access Without a Password

A critical authentication bypass in Kentico Xperience CMS lets attackers log in with only a username, chain to file-write, and execute code. Fixed in 13.0.178; CISA confirms active exploitation since Dec 2024.

Radical Notion Team6 months ago
Previous

Page 2 of 2

Next