Skip to main content

Updated in real time

What defenders are talking about right now

Live rankings from mentions, exploit signals, and public PoC evidence.

Window
24h
Ranked CVEs
25

Window: 24h

Ranked CVEs

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…

CVSS 5.9 · Medium
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed7 public PoC repos

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
54.9
KEV listed10 public PoC repos

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicati…

CVSS 9.1 · Critical
Mentions
3
Sources
3 / 3 cat.
Buzz
53.9
KEV listed

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
3
Sources
3 / 2 cat.
Buzz
50.4
KEV listed

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticat…

CVSS 8.1 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic…

CVSS 5.4 · Medium
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives…

CVSS 7.2 · High
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote…

CVSS 9.8 · Critical
Mentions
1
Sources
1 / 1 cat.
Buzz
36.9
KEV listed

The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-…

CVSS 6.4 · Medium
Mentions
11
Sources
2 / 2 cat.
Buzz
34.9

diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. In…

CVSS 2.1 · Low
Mentions
4
Sources
3 / 3 cat.
Buzz
31.1

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When…

CVSS N/A · Unknown
Mentions
4
Sources
4 / 2 cat.
Buzz
29.1

Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone pro…

CVSS 6.9 · Medium
Mentions
3
Sources
3 / 3 cat.
Buzz
28.9

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-b…

CVSS 4.3 · Medium
Mentions
3
Sources
3 / 3 cat.
Buzz
28.9

A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin En…

CVSS 1.9 · Low
Mentions
8
Sources
2 / 1 cat.
Buzz
28.5

A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/loc…

CVSS 4.8 · Medium
Mentions
8
Sources
2 / 1 cat.
Buzz
28.5

The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ…

CVSS 6.5 · Medium
Mentions
5
Sources
2 / 2 cat.
Buzz
27.9

An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.

CVSS N/A · Unknown
Mentions
4
Sources
3 / 2 cat.
Buzz
27.6

A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d configuration entry that writes to a file, systemd-tmpfiles can follow a symbolic…

CVSS 6.3 · Medium
Mentions
4
Sources
3 / 2 cat.
Buzz
27.6

A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the…

CVSS 1.9 · Low
Mentions
6
Sources
2 / 1 cat.
Buzz
26.0

Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoin…

CVSS 5.3 · Medium
Mentions
6
Sources
2 / 1 cat.
Buzz
26.0

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure…

CVSS 6.8 · Medium
Mentions
3
Sources
3 / 2 cat.
Buzz
25.4

Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML…

CVSS 5.3 · Medium
Mentions
3
Sources
3 / 2 cat.
Buzz
25.4

InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts at…

CVSS 6.3 · Medium
Mentions
5
Sources
2 / 1 cat.
Buzz
24.4

BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protec…

CVSS N/A · Unknown
Mentions
3
Sources
2 / 2 cat.
Buzz
23.9

An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the po…

CVSS N/A · Unknown
Mentions
3
Sources
2 / 2 cat.
Buzz
23.9