Trending now
Top 10 CVEs trending on social media within the last 24 hours.
Updated an hour ago
FeedsHypemeter
Current score
Colder than a datacentre floor
Trending
Hype score
Published
Description
Last 24 hours
- show more detail1CVE-2024-6100
high 8.8
13
Jun 20, 2024
CVE-2024-6100 is a "Type Confusion" vulnerability found in the V8 JavaScript engine, which is a core component of Google Chrome. This flaw occurs when a program allocates or initializes a resource with one data type but then attempts to access it using an incompatible type. This discrepancy can lead to unexpected behavior within the software. Exploitation of CVE-2024-6100 can be achieved by a remote attacker who crafts a malicious HTML page. If a user running a vulnerable version of Google Chrome (specifically, versions prior to 126.0.6478.114) visits this specially designed page, the type confusion error in the V8 engine can be triggered. This allows the attacker to execute arbitrary code within the context of the browser.
- show more detail2CVE-2025-8045
medium 4.0
8
Dec 1, 2025
CVE-2025-8045 is a "Use After Free" vulnerability affecting the Arm Ltd Valhall GPU Kernel Driver and Arm 5th Gen GPU Architecture Kernel Driver. This flaw allows a local non-privileged user process to execute improper GPU processing operations, thereby gaining access to memory that has already been freed. The vulnerability impacts driver versions r53p0 through r54p1 for both the Valhall GPU Kernel Driver and the Arm 5th Gen GPU Architecture Kernel Driver. Successful exploitation of this issue can result in the disclosure of kernel memory contents to an unprivileged process running on the device, requiring local access and no user interaction.
Valhall GPU Kernel DriverArm 5th Gen GPU Architecture Kernel Driver - show more detail3CVE-2026-18577
high 8.2
Exploit known
7
Aug 2, 2026
CVE-2026-18577 is an authentication bypass and account takeover vulnerability affecting N-able N-central versions through 2026.3.1. This flaw is a result of an incomplete patch for a previously identified vulnerability, CVE-2026-18556. Successful exploitation of CVE-2026-18577 allows remote attackers to gain administrative access to vulnerable N-central servers. Once administrative control is established, attackers can abuse the built-in "Take Control" feature to pivot into managed endpoints, deploy scripts, run tools, initiate remote-control sessions, and establish persistence within the compromised environment. The vulnerability impacts both hosted and on-premises deployments of N-able N-central.
N-central - show more detail4
6
Aug 7, 2026
CVE-2026-64638 is a pre-authentication reflected Cross-Site Scripting (XSS) vulnerability present in the login screen of all WordPress versions. This flaw allows for the execution of XSS without requiring attacker privileges or direct victim interaction once a specially crafted request is delivered. The vulnerability originates from how WordPress processes the username during a failed login attempt, specifically concerning the `sanitize_user()` and `wp_strip_all_tags()` functions, which can mishandle tag-like strings containing whitespace. Under specific circumstances, this XSS vulnerability can be escalated to achieve PHP code execution on the server. This escalation path is more involved, typically requiring a victim who is already logged in as a single-site Administrator to interact with an attacker-controlled page, alongside certain WordPress features and deployment conditions being met. WordPress addressed this issue in version 7.0.3, with fixes also backported to versions as far back as 4.7.
xss2shell - show more detail5CVE-2026-11331
high 7.5
5
Jul 22, 2026
CVE-2026-11331 describes a vulnerability within the BIND 9 software that affects its Response Policy Zone (RPZ) processing. An attacker can exploit this by crafting DNS query names that are excessively long. If a resolver uses RPZ with wildcard CNAME policies, these long query names can trigger a "NAMETOOLONG" error condition during processing. The vulnerability arises because this error condition is not handled correctly by the BIND 9 software. This improper handling can lead to two primary outcomes: either the RPZ rule is defeated, allowing the attacker to bypass intended security policies, or the BIND 9 software may terminate unexpectedly. This issue impacts various versions of BIND 9, including 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, and 9.21.0 through 9.21.23, as well as specific S1 releases.
Dns - show more detail6CVE-2026-27912
high 8.0
4
Apr 14, 2026
CVE-2026-27912 is an improper authorization vulnerability found within Windows Kerberos. This flaw allows an authorized attacker to elevate their privileges when operating over an adjacent network. The vulnerability, classified under CWE-285 (Improper Authorization), stems from the Kerberos authentication protocol's failure to properly validate authorization controls. This enables attackers with initial network access to bypass authorization checks and gain elevated privileges within the affected Windows environment. This vulnerability is also referred to as "ResetNightmare".
- show more detail7CVE-2026-20303
critical 9.9
1
Aug 5, 2026
CVE-2026-20303 identifies a collection of vulnerabilities within Cisco Catalyst SD-WAN Software, primarily stemming from improper input validation issues. These vulnerabilities are grouped under the Common Weakness Enumeration (CWE) CWE-20, representing a change in Cisco's typical disclosure approach where multiple underlying security defects are consolidated under a single CVE based on their common weakness class. This particular grouping encompasses problems such as input validation failures, path traversal, and external path control. The affected software includes Cisco Catalyst SD-WAN deployments across on-premises, Cisco SD-WAN Cloud-Pro, Cisco-managed SD-WAN Cloud, and Cisco SD-WAN for Government environments, regardless of device configuration. Cisco has released software hardening updates to address these internally discovered vulnerabilities, and no workarounds are available.
- show more detail8CVE-2026-20304
critical 9.9
1
Aug 5, 2026
CVE-2026-20304 identifies a set of vulnerabilities within Cisco Catalyst SD-WAN software, stemming from improper access control issues. These flaws are categorized under the Common Weakness Enumeration (CWE) CWE-284. The vulnerabilities were discovered internally by the Cisco Catalyst SD-WAN engineering team during a comprehensive security review. This CVE is part of a broader software hardening release by Cisco, which addresses multiple internally identified security concerns. The improper access control issues could potentially allow an attacker with low-level privileges to bypass security controls.
- show more detail9CVE-2026-20272
critical 9.8
1
Aug 5, 2026
CVE-2026-20272 identifies a group of vulnerabilities within Cisco IOS XE software, stemming from the improper neutralization of special elements. This collection of internally discovered weaknesses is categorized under CWE-74, which broadly covers injection issues such as command injection, operating system command injection, and argument injection. Rather than a single, conventional vulnerability with a specific exploitation path, CVE-2026-20272 acts as an umbrella identifier for multiple related bugs. Cisco's engineering team uncovered these issues during a comprehensive internal security review, leading to the release of software hardening updates to address them.
- show more detail10CVE-2026-20267
critical 9.0
1
Aug 5, 2026
CVE-2026-20267 is an improper access control vulnerability (CWE-284) affecting Cisco IOS XE Software. This flaw was identified internally by Cisco's engineering team during a thorough security review, which leveraged both existing testing methodologies and advanced AI models. The vulnerability could potentially lead to authentication or authorization bypass within affected Cisco IOS XE Software, which runs in autonomous or controller mode. It is part of a series of internally discovered issues addressed in recent software hardening releases for various Cisco IOS XE Software versions, including release trains 17.9, 17.12, 17.15, 17.18, and 26.1.
- show more detail
Hype score
8
·
medium 4.0
Valhall GPU Kernel DriverArm 5th Gen GPU Architecture Kernel Driver