Skip to main content

Updated in real time

What defenders are talking about right now

Live rankings from mentions, exploit signals, and public PoC evidence.

Window
7d
Ranked CVEs
25

Window: 7d

Ranked CVEs

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicati…

CVSS 9.1 · Critical
Mentions
17
Sources
11 / 5 cat.
Buzz
73.9
KEV listed

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
13
Sources
6 / 3 cat.
Buzz
70.9
KEV listed

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives…

CVSS 7.2 · High
Mentions
12
Sources
11 / 3 cat.
Buzz
70.7
KEV listed

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…

CVSS 5.9 · Medium
Mentions
3
Sources
3 / 2 cat.
Buzz
68.4
KEV listed8 public PoC repos

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…

CVSS 9.8 · Critical
Mentions
3
Sources
3 / 2 cat.
Buzz
68.4
KEV listed11 public PoC repos

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…

CVSS 10.0 · Critical
Mentions
7
Sources
7 / 4 cat.
Buzz
65.8
KEV listed

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_h…

CVSS 7.8 · High
Mentions
19
Sources
9 / 6 cat.
Buzz
56.1
1 public PoC repos

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg…

CVSS 7.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed4 public PoC repos

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the…

CVSS 10.0 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed7 public PoC repos

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi…

CVSS 7.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed6 public PoC repos

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass se…

CVSS 7.8 · High
Mentions
5
Sources
2 / 1 cat.
Buzz
54.0
KEV listed1 public PoC repos

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudo…

CVSS 7.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
52.3
KEV listed3 public PoC repos

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote…

CVSS 8.6 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS…

CVSS 5.9 · Medium
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

CVSS 10.0 · Critical
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…

CVSS 7.2 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote att…

CVSS 9.3 · Critical
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. In…

CVSS 2.1 · Low
Mentions
5
Sources
4 / 4 cat.
Buzz
37.9

TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has…

CVSS 9.8 · Critical
Mentions
6
Sources
5 / 3 cat.
Buzz
37.5

vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the…

CVSS 9.3 · Critical
Mentions
6
Sources
5 / 3 cat.
Buzz
37.5

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 200…

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticat…

CVSS 8.1 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic…

CVSS 5.4 · Medium
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote…

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed