Skip to main content

Updated in real time

What defenders are talking about right now

Live rankings from mentions, exploit signals, and public PoC evidence.

Window
7d
Ranked CVEs
25

Window: 7d

Ranked CVEs

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7.0 · High
Mentions
23
Sources
19 / 4 cat.
Buzz
75.0
KEV listed

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access…

CVSS 10.0 · Critical
Mentions
7
Sources
7 / 6 cat.
Buzz
65.8
KEV listed

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall T…

CVSS 8.6 · High
Mentions
7
Sources
7 / 5 cat.
Buzz
65.8
KEV listed

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
8
Sources
4 / 1 cat.
Buzz
56.5
KEV listed

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed3 public PoC repos

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi…

CVSS 7.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed7 public PoC repos

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS 7.8 · High
Mentions
4
Sources
4 / 2 cat.
Buzz
54.1
KEV listed

Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is n…

CVSS 9.9 · Critical
Mentions
5
Sources
5 / 1 cat.
Buzz
53.9
KEV listed

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CVSS 8.2 · High
Mentions
6
Sources
3 / 1 cat.
Buzz
52.5
KEV listed

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary com…

CVSS 9.6 · Critical
Mentions
3
Sources
3 / 2 cat.
Buzz
50.4
KEV listed

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach…

CVSS 8.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
48.0
KEV listed2 public PoC repos

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges lo…

CVSS 7.8 · High
Mentions
14
Sources
14 / 2 cat.
Buzz
47.1

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS 5.3 · Medium
Mentions
3
Sources
3 / 1 cat.
Buzz
46.9
KEV listed

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS 7.8 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log…

CVSS 5.3 · Medium
Mentions
2
Sources
2 / 2 cat.
Buzz
46.0
KEV listed

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
12
Sources
12 / 2 cat.
Buzz
45.6

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hoste…

CVSS 8.9 · High
Mentions
6
Sources
6 / 5 cat.
Buzz
45.0
1 public PoC repos

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized att…

CVSS 5.5 · Medium
Mentions
11
Sources
11 / 2 cat.
Buzz
44.9

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
44.4
KEV listed1 public PoC repos

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

CVSS 7.3 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
44.4
KEV listed1 public PoC repos

Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
9
Sources
9 / 2 cat.
Buzz
43.0

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

CVSS 8.0 · High
Mentions
9
Sources
9 / 2 cat.
Buzz
43.0

In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injectin…

CVSS N/A · Unknown
Mentions
14
Sources
3 / 3 cat.
Buzz
42.1

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS 8.8 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
41.5
KEV listed1 public PoC repos