Skip to main content

Updated in real time

What defenders are talking about right now

Live rankings from mentions, exploit signals, and public PoC evidence.

Window
7d
Ranked CVEs
25

Window: 7d

Ranked CVEs

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7.0 · High
Mentions
27
Sources
19 / 4 cat.
Buzz
75.0
KEV listed

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access…

CVSS 10.0 · Critical
Mentions
10
Sources
9 / 7 cat.
Buzz
69.0
KEV listed

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall T…

CVSS 8.6 · High
Mentions
10
Sources
8 / 5 cat.
Buzz
69.0
KEV listed

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n…

CVSS 9.9 · Critical
Mentions
6
Sources
6 / 2 cat.
Buzz
60.5
KEV listed

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg…

CVSS 7.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed4 public PoC repos

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed3 public PoC repos

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…

CVSS 5.9 · Medium
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed11 public PoC repos

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed14 public PoC repos

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS 7.8 · High
Mentions
4
Sources
4 / 2 cat.
Buzz
54.1
KEV listed

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CVSS 8.2 · High
Mentions
6
Sources
3 / 1 cat.
Buzz
52.5
KEV listed

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudo…

CVSS 7.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
52.3
KEV listed3 public PoC repos

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges lo…

CVSS 7.8 · High
Mentions
15
Sources
15 / 2 cat.
Buzz
47.7

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in…

CVSS 10.0 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
47.4
KEV listed2 public PoC repos

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…

CVSS 9.3 · Critical
Mentions
2
Sources
2 / 1 cat.
Buzz
47.1
KEV listed1 public PoC repos

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

CVSS 10.0 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
46.9
KEV listed2 public PoC repos

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy ver…

CVSS 9.8 · Critical
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS 7.8 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 throu…

CVSS 8.1 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
12
Sources
12 / 2 cat.
Buzz
45.6

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized att…

CVSS 5.5 · Medium
Mentions
11
Sources
11 / 2 cat.
Buzz
44.9

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
44.4
KEV listed1 public PoC repos

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

CVSS 7.3 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
44.4
KEV listed1 public PoC repos

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
10
Sources
10 / 2 cat.
Buzz
44.0

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

CVSS 10.0 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
43.0
KEV listed1 public PoC repos