Skip to main content

Updated in real time

What defenders are talking about right now

Live rankings from mentions, exploit signals, and public PoC evidence.

Window
7d
Ranked CVEs
25

Window: 7d

Ranked CVEs

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CVSS 8.2 · High
Mentions
17
Sources
15 / 9 cat.
Buzz
73.9
KEV listed

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-centra…

CVSS 8.2 · High
Mentions
7
Sources
6 / 4 cat.
Buzz
65.8
KEV listed

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVSS 9.8 · Critical
Mentions
6
Sources
6 / 3 cat.
Buzz
64.0
KEV listed

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
13
Sources
4 / 1 cat.
Buzz
60.9
KEV listed

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg…

CVSS 7.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed4 public PoC repos

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi…

CVSS 7.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed7 public PoC repos

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit…

CVSS 9.8 · Critical
Mentions
4
Sources
4 / 2 cat.
Buzz
54.1
KEV listed

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudo…

CVSS 7.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
52.3
KEV listed3 public PoC repos

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log…

CVSS 5.3 · Medium
Mentions
3
Sources
3 / 2 cat.
Buzz
50.4
KEV listed

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary com…

CVSS 9.6 · Critical
Mentions
3
Sources
3 / 2 cat.
Buzz
50.4
KEV listed

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

CVSS 10.0 · Critical
Mentions
2
Sources
2 / 1 cat.
Buzz
48.6
KEV listed1 public PoC repos

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach…

CVSS 8.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
48.0
KEV listed2 public PoC repos

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_a…

CVSS 9.8 · Critical
Mentions
14
Sources
5 / 4 cat.
Buzz
47.1

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.…

CVSS 7.5 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Ch…

CVSS 8.8 · High
Mentions
9
Sources
5 / 4 cat.
Buzz
43.0

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbit…

CVSS 8.8 · High
Mentions
6
Sources
5 / 3 cat.
Buzz
43.0
1 public PoC repos

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…

CVSS 7.2 · High
Mentions
2
Sources
2 / 1 cat.
Buzz
42.5
KEV listed

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS 5.3 · Medium
Mentions
2
Sources
2 / 1 cat.
Buzz
42.5
KEV listed

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue a…

CVSS 8.7 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
42.5
KEV listed1 public PoC repos

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

CVSS 10.0 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
42.4
KEV listed1 public PoC repos

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use…

CVSS 8.7 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
42.1
KEV listed1 public PoC repos

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks au…

CVSS 9.3 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
41.9
KEV listed1 public PoC repos

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass se…

CVSS 7.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
41.5
KEV listed1 public PoC repos

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…

CVSS 9.3 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
41.5
KEV listed1 public PoC repos

In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injectin…

CVSS N/A · Unknown
Mentions
13
Sources
3 / 3 cat.
Buzz
41.4