Skip to main content

Updated in real time

What defenders are talking about right now

Live rankings from mentions, exploit signals, and public PoC evidence.

Window
7d
Ranked CVEs
25

Window: 7d

Ranked CVEs

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log…

CVSS 5.3 · Medium
Mentions
9
Sources
9 / 5 cat.
Buzz
68.0
KEV listed

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…

CVSS 10.0 · Critical
Mentions
8
Sources
8 / 4 cat.
Buzz
67.0
KEV listed

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg…

CVSS 7.8 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
64.0
KEV listed4 public PoC repos

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi…

CVSS 7.8 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
64.0
KEV listed6 public PoC repos

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudo…

CVSS 7.8 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
61.4
KEV listed3 public PoC repos

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
11
Sources
3 / 2 cat.
Buzz
61.4
KEV listed

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives…

CVSS 7.2 · High
Mentions
6
Sources
5 / 2 cat.
Buzz
59.0
KEV listed

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicati…

CVSS 9.1 · Critical
Mentions
7
Sources
4 / 2 cat.
Buzz
58.8
KEV listed

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass se…

CVSS 7.8 · High
Mentions
4
Sources
3 / 2 cat.
Buzz
57.2
KEV listed1 public PoC repos

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the…

CVSS 10.0 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed7 public PoC repos

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…

CVSS 5.9 · Medium
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed8 public PoC repos

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed11 public PoC repos

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS…

CVSS 5.9 · Medium
Mentions
3
Sources
3 / 2 cat.
Buzz
50.4
KEV listed

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to…

CVSS 8.1 · High
Mentions
3
Sources
3 / 1 cat.
Buzz
46.9
KEV listed

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not di…

CVSS 9.5 · Critical
Mentions
13
Sources
5 / 4 cat.
Buzz
46.4

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

CVSS 10.0 · Critical
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…

CVSS 7.2 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue a…

CVSS 8.7 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
42.5
KEV listed1 public PoC repos

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…

CVSS 9.3 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
41.5
KEV listed1 public PoC repos

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros…

CVSS 6.4 · Medium
Mentions
17
Sources
3 / 2 cat.
Buzz
40.4

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the…

CVSS 9.3 · Critical
Mentions
7
Sources
6 / 3 cat.
Buzz
40.3

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros…

CVSS 6.4 · Medium
Mentions
15
Sources
3 / 2 cat.
Buzz
39.2

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions…

CVSS 7.2 · High
Mentions
15
Sources
3 / 2 cat.
Buzz
39.2

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to th…

CVSS 7.5 · High
Mentions
8
Sources
4 / 3 cat.
Buzz
38.5

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, ma…

CVSS 9.8 · Critical
Mentions
9
Sources
3 / 3 cat.
Buzz
38.0