Trending now
Top 10 CVEs trending on social media within the last 24 hours.
Updated an hour ago
FeedsHypemeter
Current score
Soft-boiled
Trending
Hype score
Published
Description
Last 24 hours
- show more detail1CVE-2025-62593
critical 9.4
Exploit known
35
Nov 26, 2025
CVE-2025-62593 describes a remote code execution (RCE) vulnerability affecting Ray, an AI compute engine, in versions prior to 2.52.0. The flaw lies in Ray's HTTP API endpoint handling, where an insufficient defense mechanism relies solely on the User-Agent header starting with "Mozilla". This defense is inadequate because the fetch specification allows for the manipulation of the User-Agent header. This vulnerability can be exploited when a developer running Ray visits a malicious website in a vulnerable browser, such as Firefox or Safari. The attack combines the User-Agent bypass with a DNS rebinding attack, tricking the browser into treating a remote attacker-controlled server and the local Ray instance as the same origin. This allows an attacker to trigger arbitrary code execution on the developer's system. The issue has been addressed in Ray version 2.52.0.
RayFirefox - show more detail2CVE-2026-33824
critical 9.8
Exploit known
27
Apr 14, 2026
CVE-2026-33824 is a double free vulnerability found within the Windows Internet Key Exchange (IKE) Extension. This memory corruption flaw allows an unauthorized attacker to execute arbitrary code over a network. The vulnerability specifically affects the Windows IPsec IKE service, which is responsible for establishing secure VPN connections and managing cryptographic key exchanges. The flaw can be exploited remotely without authentication or user interaction by sending specially crafted UDP packets to ports 500 (IKE) or 4500 (NAT-T IKE) on a vulnerable Windows system. These malicious packets trigger the double free condition during IKE message parsing, potentially leading to heap corruption and ultimately enabling remote code execution.
VPNNetwork - show more detail3CVE-2026-59310
critical 9.8
Exploit known
25
Jul 30, 2026
CVE-2026-59310 is identified as a directory traversal vulnerability present in the VMware vCenter Syslog server. This flaw enables a remote, unauthenticated attacker with network access to a susceptible vCenter instance to manipulate file and directory paths beyond their intended boundaries. Successful exploitation of this vulnerability can lead to arbitrary code execution on the affected vCenter system. The issue impacts VMware vCenter and other VMware platforms that incorporate the vulnerable vCenter component.
Syslog ServerZero-day - show more detail4CVE-2026-65400
critical 9.8
Exploit known
25
Aug 6, 2026
CVE-2026-65400 is an authentication bypass vulnerability affecting the Screen Sharing service in macOS. This flaw allows an attacker on the network to authenticate to Screen Sharing without needing valid credentials. The vulnerability stems from an issue with improved state management, specifically an error in the implementation of Secure Remote Password (SRP) authentication where the daemon's frame-length validator incorrectly returns a stale success status, leading to a connection being treated as authenticated when it is not. Successful exploitation of CVE-2026-65400 can grant unauthorized remote access to affected macOS systems. Security researchers have indicated that exploitation can extend beyond merely viewing a user's screen, potentially allowing an attacker to gain substantial control, including root access, over the compromised Mac. Apple released patches for this vulnerability on August 6, 2026, for macOS Sequoia (version 15.7.9), macOS Sonoma (version 14.8.9), and macOS Tahoe (version 26.6.1).
Supply chainZero-day - show more detail5CVE-2026-55040
critical 9.1
Exploit known
25
Jul 14, 2026
CVE-2026-55040 is an authentication bypass vulnerability affecting Microsoft SharePoint Server. This flaw stems from issues within the JSON Web Token (JWT) validation pipeline, allowing a remote, unauthenticated attacker to bypass the authentication process. By exploiting this vulnerability, an attacker can assume the identity of any SharePoint site user, provided they know the target user's Active Directory Security ID (SID) or User Principal Name (UPN). This authentication bypass can be chained with other vulnerabilities to achieve further compromise, such as unauthenticated remote code execution. The vulnerability was discovered by Rapid7 Labs during a zero-day research project.
Microsoft Office SharePointJwt - show more detail6CVE-2026-74970
medium 5.4
10
Aug 18, 2026
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- show more detail7
10
Aug 18, 2026
CVE-2026-74943 describes a vulnerability found in the "Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content" WordPress plugin, specifically in versions prior to 2.8.4. This flaw allows unauthenticated users to bypass the sitewide password protection. The vulnerability stems from an insufficient restriction of REST API access for authenticated users when a particular option is enabled. This oversight permits unauthenticated visitors to read content that should otherwise be protected, including account identifiers, by directly accessing the REST API. This issue is a re-introduction of a previously patched vulnerability, CVE-2024-0437, which was initially fixed in version 2.6.7 but reappeared in version 2.6.8 of the plugin.
WordPress - show more detail8
10
Aug 18, 2026
Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- show more detail9CVE-2025-1098
high 8.8
9
Mar 25, 2025
CVE-2025-1098 is one of five critical vulnerabilities disclosed in the Ingress NGINX Controller for Kubernetes. These vulnerabilities, collectively named "IngressNightmare," could lead to unauthenticated remote code execution. The vulnerability affects the admission controller component and allows attackers to inject arbitrary Nginx configurations by sending malicious ingress objects. This can result in code execution on the Ingress NGINX Controller's pod and unauthorized access to all secrets stored across all namespaces in the Kubernetes cluster, potentially leading to a complete cluster takeover.
KubernetesNGINX - show more detail10CVE-2026-73268
critical 9.9
1
Aug 12, 2026
CVE-2026-73268 is a code injection vulnerability found within the `cluster-curator-controller` component of the Multicluster Engine (MCE). The flaw allows a tenant possessing create or update permissions on `ClusterCurator` resources to inject an arbitrary Job specification. This occurs because the `CreateJob()` function fails to validate user-controlled input when unmarshaling the `spec.install.overrideJob` raw extension. Successful exploitation of this vulnerability enables the injected Job to execute with the elevated privileges of the controller. This can lead to arbitrary code execution, privilege escalation, and potential access to sensitive cluster-wide secrets.
- show more detail
Hype score
25
·
critical 9.1
Exploit known
Microsoft Office SharePointJwt