Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/Trending Threats
Trending Threats

What's dangerous right now

The newest confirmed exploited-in-the-wild vulnerabilities (CISA KEV), ransomware-linked CVEs, and the latest malicious open-source package incidents.

Newly added to CISA KEV

CVE-2026-56291Balbooa Forms2026-07-10CVE-2026-48939iCagenda iCagenda2026-07-10CVE-2026-48908JoomShaper SP Page Builder2026-07-07CVE-2026-55255Langflow Langflow2026-07-07CVE-2026-56290Joomlack Page Builder2026-07-07CVE-2026-48282Adobe ColdFusion2026-07-07CVE-2026-45659Microsoft SharePoint Server2026-07-01CVE-2026-48558SimpleHelp SimpleHelp2026-06-29CVE-2026-12569PTC Windchill and FlexPLM2026-06-25CVE-2026-20230Cisco Unified Communications Manager2026-06-25
All 1,637 actively-exploited CVEs

Latest supply-chain attacks

@solana/web3.jscompromise · 2024polyfill.io (polyfill-service)compromise · 2024xz / liblzmabackdoor · 2024@ledgerhq/connect-kitcompromise · 2023PyTorch / discordpydebug & similarmalicious · 2023web3-essential / crypto typosquatstyposquat · 2023colors / fakerprotestware · 2022ctxcompromise · 2022node-ipcprotestware · 2022torchtriton (pytorch-nightly)dependency-confusion · 2022
All malicious packages

Ransomware-linked

CVE-2026-35273CVE-2026-50751CVE-2026-48027CVE-2026-45321CVE-2026-41940CVE-2024-1708CVE-2024-57728CVE-2024-57726CVE-2026-33825CVE-2023-27351

Get alerted the moment a threat hits your stack

Don’t watch a feed — let Safeguard match new exploited CVEs and malicious packages against your actual dependencies and tell you if you’re affected.

Monitor my stack free See pricing

Sources: CISA Known Exploited Vulnerabilities catalog and Safeguard's curated malicious-package index. See Credits & Data Sources.