Skip to main content

Updated in real time

What defenders are talking about right now

Live rankings from mentions, exploit signals, and public PoC evidence.

Window
30d
Ranked CVEs
25

Window: 30d

Ranked CVEs

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…

CVSS 9.8 · Critical
Mentions
21
Sources
17 / 8 cat.
Buzz
93.0
KEV listed10 public PoC repos

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…

CVSS 5.9 · Medium
Mentions
20
Sources
16 / 7 cat.
Buzz
93.0
KEV listed7 public PoC repos

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to fu…

CVSS 10.0 · Critical
Mentions
8
Sources
8 / 7 cat.
Buzz
79.2
KEV listed2 public PoC repos

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS 8.8 · High
Mentions
16
Sources
8 / 3 cat.
Buzz
77.9
KEV listed1 public PoC repos

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS 5.3 · Medium
Mentions
33
Sources
21 / 4 cat.
Buzz
75.0
KEV listed

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locall…

CVSS 7.8 · High
Mentions
25
Sources
21 / 4 cat.
Buzz
75.0
KEV listed

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

CVSS 10.0 · Critical
Mentions
22
Sources
14 / 7 cat.
Buzz
75.0
KEV listed

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

CVSS 10.0 · Critical
Mentions
22
Sources
10 / 5 cat.
Buzz
75.0
KEV listed

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
22
Sources
15 / 4 cat.
Buzz
75.0
KEV listed

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…

CVSS 7.2 · High
Mentions
20
Sources
13 / 6 cat.
Buzz
75.0
KEV listed

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · Critical
Mentions
17
Sources
13 / 4 cat.
Buzz
73.9
KEV listed

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.…

CVSS 9.8 · Critical
Mentions
17
Sources
7 / 3 cat.
Buzz
73.9
KEV listed

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…

CVSS 9.3 · Critical
Mentions
10
Sources
7 / 3 cat.
Buzz
73.6
KEV listed1 public PoC repos

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerabili…

CVSS 8.4 · High
Mentions
15
Sources
10 / 5 cat.
Buzz
72.7
KEV listed

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM…

CVSS 8.6 · High
Mentions
14
Sources
9 / 5 cat.
Buzz
72.1
KEV listed

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi…

CVSS 7.8 · High
Mentions
4
Sources
3 / 2 cat.
Buzz
70.6
KEV listed6 public PoC repos

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full…

CVSS 10.0 · Critical
Mentions
7
Sources
7 / 5 cat.
Buzz
70.4
KEV listed1 public PoC repos

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. Whe…

CVSS 9.5 · Critical
Mentions
11
Sources
9 / 4 cat.
Buzz
69.8
KEV listed

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVSS 6.5 · Medium
Mentions
11
Sources
7 / 3 cat.
Buzz
69.8
KEV listed

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

CVSS 9.8 · Critical
Mentions
6
Sources
6 / 2 cat.
Buzz
69.0
KEV listed2 public PoC repos

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can…

CVSS 9.8 · Critical
Mentions
9
Sources
8 / 3 cat.
Buzz
68.0
KEV listed

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP…

CVSS 10.0 · Critical
Mentions
5
Sources
5 / 2 cat.
Buzz
67.8
KEV listed2 public PoC repos

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticat…

CVSS 8.1 · High
Mentions
8
Sources
8 / 5 cat.
Buzz
67.0
KEV listed

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0…

CVSS 9.8 · Critical
Mentions
7
Sources
7 / 3 cat.
Buzz
65.8
KEV listed

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and C…

CVSS 7.8 · High
Mentions
10
Sources
6 / 2 cat.
Buzz
65.0
KEV listed