Skip to main content

Updated in real time

What defenders are talking about right now

Live rankings from mentions, exploit signals, and public PoC evidence.

Window
7d
Ranked CVEs
25

Window: 7d

Ranked CVEs

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CVSS 8.2 · High
Mentions
16
Sources
15 / 9 cat.
Buzz
73.3
KEV listed

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-centra…

CVSS 8.2 · High
Mentions
10
Sources
9 / 7 cat.
Buzz
69.0
KEV listed

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log…

CVSS 5.3 · Medium
Mentions
7
Sources
7 / 3 cat.
Buzz
65.8
KEV listed

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.…

CVSS 9.8 · Critical
Mentions
5
Sources
5 / 3 cat.
Buzz
60.9
KEV listed

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVSS 9.8 · Critical
Mentions
5
Sources
5 / 3 cat.
Buzz
60.9
KEV listed

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…

CVSS 9.3 · Critical
Mentions
4
Sources
4 / 2 cat.
Buzz
58.7
KEV listed1 public PoC repos

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to…

CVSS 8.1 · High
Mentions
5
Sources
5 / 2 cat.
Buzz
57.4
KEV listed

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not di…

CVSS 9.5 · Critical
Mentions
23
Sources
11 / 4 cat.
Buzz
55.5
1 public PoC repos

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
10
Sources
2 / 1 cat.
Buzz
55.5
KEV listed

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi…

CVSS 7.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed6 public PoC repos

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

CVSS 9.3 · Critical
Mentions
4
Sources
4 / 2 cat.
Buzz
54.1
KEV listed

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks au…

CVSS 9.3 · Critical
Mentions
4
Sources
4 / 2 cat.
Buzz
54.1
KEV listed

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit…

CVSS 9.8 · Critical
Mentions
4
Sources
4 / 2 cat.
Buzz
54.1
KEV listed

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remo…

CVSS 9.9 · Critical
Mentions
4
Sources
3 / 2 cat.
Buzz
52.6
KEV listed

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an un…

CVSS 9.3 · Critical
Mentions
3
Sources
3 / 2 cat.
Buzz
50.4
KEV listed

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

CVSS 10.0 · Critical
Mentions
2
Sources
2 / 1 cat.
Buzz
48.0
KEV listed1 public PoC repos

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass se…

CVSS 7.8 · High
Mentions
2
Sources
1 / 1 cat.
Buzz
45.6
KEV listed1 public PoC repos

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…

CVSS 7.2 · High
Mentions
2
Sources
2 / 1 cat.
Buzz
42.5
KEV listed

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue a…

CVSS 8.7 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
42.5
KEV listed1 public PoC repos

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use…

CVSS 8.7 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
42.1
KEV listed1 public PoC repos

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to th…

CVSS 7.5 · High
Mentions
8
Sources
4 / 3 cat.
Buzz
38.5

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

CVSS 9.4 · Critical
Mentions
4
Sources
4 / 3 cat.
Buzz
38.1
1 public PoC repos

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers a…

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm…

CVSS 8.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives…

CVSS 7.2 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed