Skip to main content

Updated in real time

What defenders are talking about right now

Live rankings from mentions, exploit signals, and public PoC evidence.

Window
7d
Ranked CVEs
25

Window: 7d

Ranked CVEs

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…

CVSS 9.8 · Critical
Mentions
22
Sources
18 / 8 cat.
Buzz
93.0
KEV listed10 public PoC repos

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…

CVSS 5.9 · Medium
Mentions
21
Sources
17 / 7 cat.
Buzz
93.0
KEV listed7 public PoC repos

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
11
Sources
8 / 3 cat.
Buzz
69.8
KEV listed

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicati…

CVSS 9.1 · Critical
Mentions
8
Sources
8 / 5 cat.
Buzz
67.0
KEV listed

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

CVSS 10.0 · Critical
Mentions
7
Sources
7 / 3 cat.
Buzz
65.8
KEV listed

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…

CVSS 7.2 · High
Mentions
7
Sources
7 / 3 cat.
Buzz
65.8
KEV listed

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
8
Sources
6 / 2 cat.
Buzz
63.0
KEV listed

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

CVSS 9.8 · Critical
Mentions
5
Sources
5 / 1 cat.
Buzz
62.4
KEV listed2 public PoC repos

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to…

CVSS 9.3 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
54.4
KEV listed3 public PoC repos

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS 5.3 · Medium
Mentions
4
Sources
4 / 2 cat.
Buzz
54.1
KEV listed

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass se…

CVSS 7.8 · High
Mentions
5
Sources
2 / 1 cat.
Buzz
54.0
KEV listed1 public PoC repos

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0…

CVSS 9.8 · Critical
Mentions
5
Sources
5 / 1 cat.
Buzz
53.9
KEV listed

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives…

CVSS 7.2 · High
Mentions
3
Sources
3 / 2 cat.
Buzz
50.4
KEV listed

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locall…

CVSS 7.8 · High
Mentions
3
Sources
3 / 2 cat.
Buzz
50.4
KEV listed

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_h…

CVSS N/A · Unknown
Mentions
13
Sources
7 / 5 cat.
Buzz
46.4

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticat…

CVSS 8.1 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote…

CVSS 9.8 · Critical
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…

CVSS 9.3 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
41.5
KEV listed1 public PoC repos

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS 8.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
41.5
KEV listed1 public PoC repos

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie…

CVSS 10.0 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
40.9
KEV listed1 public PoC repos

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's rege…

CVSS 9.2 · Critical
Mentions
9
Sources
3 / 2 cat.
Buzz
39.5
1 public PoC repos

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fanc…

CVSS 6.4 · Medium
Mentions
10
Sources
3 / 3 cat.
Buzz
39.0

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'red…

CVSS 6.1 · Medium
Mentions
8
Sources
4 / 3 cat.
Buzz
38.5

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information r…

CVSS 6.5 · Medium
Mentions
5
Sources
5 / 4 cat.
Buzz
37.9

diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. In…

CVSS 2.1 · Low
Mentions
5
Sources
4 / 4 cat.
Buzz
37.9