Trending now
Top 10 CVEs trending on social media within the last 24 hours.
Updated 28 minutes ago
FeedsHypemeter
Current score
Colder than a datacentre floor
Trending
Hype score
Published
Description
Last 24 hours
- show more detail1CVE-2025-8045
medium 4.0
8
Dec 1, 2025
CVE-2025-8045 is a "Use After Free" vulnerability affecting the Arm Ltd Valhall GPU Kernel Driver and Arm 5th Gen GPU Architecture Kernel Driver. This flaw allows a local non-privileged user process to execute improper GPU processing operations, thereby gaining access to memory that has already been freed. The vulnerability impacts driver versions r53p0 through r54p1 for both the Valhall GPU Kernel Driver and the Arm 5th Gen GPU Architecture Kernel Driver. Successful exploitation of this issue can result in the disclosure of kernel memory contents to an unprivileged process running on the device, requiring local access and no user interaction.
Valhall GPU Kernel DriverArm 5th Gen GPU Architecture Kernel Driver - show more detail2CVE-2026-18577
high 8.2
Exploit known
7
Aug 2, 2026
CVE-2026-18577 is an authentication bypass and account takeover vulnerability affecting N-able N-central versions through 2026.3.1. This flaw is a result of an incomplete patch for a previously identified vulnerability, CVE-2026-18556. Successful exploitation of CVE-2026-18577 allows remote attackers to gain administrative access to vulnerable N-central servers. Once administrative control is established, attackers can abuse the built-in "Take Control" feature to pivot into managed endpoints, deploy scripts, run tools, initiate remote-control sessions, and establish persistence within the compromised environment. The vulnerability impacts both hosted and on-premises deployments of N-able N-central.
N-central - show more detail3CVE-2025-15039
critical 9.4
4
Aug 6, 2026
CVE-2025-15039 describes a vulnerability found in the Conditional Authentication (Adaptive Authentication) script used across several WSO2 products, including API Control Plane, API Manager, Carbon Identity Application Authentication Framework, Identity Server, Identity Server as Key Manager, Open Banking AM, Open Banking IAM, Traffic Manager, and Universal Gateway. This flaw allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation of CVE-2025-15039 can lead to unauthorized access to a targeted user account. This vulnerability is exploitable under specific conditions: the application's login flow must include a particular secondary authenticator, the Conditional Authentication script needs to be configured with specific event callbacks and re-execute an authentication step, the targeted user must have one of the impacted authenticators enrolled, and the attacker must successfully complete any preceding authentication steps.
- show more detail4CVE-2025-14499
high 8.8
4
Dec 23, 2025
CVE-2025-14499 is identified as an IceWarp gmaps Cross-Site Scripting (XSS) Authentication Bypass Vulnerability. This flaw enables remote attackers to bypass authentication on affected installations of IceWarp. The vulnerability stems from improper validation of user-supplied data within a parameter passed to the gmaps webpage, allowing for the injection of arbitrary scripts. Exploitation requires user interaction, as the target must visit a malicious page or open a malicious file.
IceWarpIceWarp gmaps - show more detail5CVE-2025-13394
medium 5.4
4
Aug 6, 2026
CVE-2025-13394 describes a Cross-Site Request Forgery (CSRF) vulnerability found in the Ajax processor of the Carbon console, which is part of WSO2 products. The issue stems from the console's use of the HTTP GET method for state-changing operations. Although the `SameSite=Lax` cookie attribute is implemented as a protective measure, this mitigation can be circumvented. This bypass allows an attacker to manipulate an authenticated user's browser into executing unintended actions without their knowledge. Such an exploit could lead to unauthorized modifications of data, changes to user accounts, or other actions that might result in data compromise or a loss of user control. However, this attack is only viable if the Carbon console and its associated services are accessible via the public internet, a configuration that WSO2's security guidelines advise against.
Carbon ConsoleWSO2 - show more detail6CVE-2026-39868
critical 9.1
3
Jun 29, 2026
CVE-2026-39868 is a kernel vulnerability affecting macOS and other Apple operating systems, including iOS, iPadOS, tvOS, visionOS, and watchOS. This flaw resides within Apple's DTrace subsystem, which is a dynamic tracing framework. An unprivileged application can exploit this vulnerability to corrupt kernel memory. The vulnerability stems from insufficient input validation within DTrace when processing a binary format called DOF. A crafted DOF can be staged by a normal, unprivileged application, and when DTrace processes this data from a trusted root context, it can lead to a confused-deputy problem. Weak section validation and an integer overflow allow attacker-chosen indices to bypass checks, resulting in out-of-bounds kernel pointers during probe setup and subsequent kernel memory corruption. Apple addressed this issue with improved input validation and released fixes in updates such as iOS 26.5.2, iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, and watchOS 26.6. A proof-of-concept exploit for CVE-2026-39868 has been publicly disclosed.
iOSiPadOS - show more detail7
3
Aug 7, 2026
CVE-2026-64638 is a pre-authentication reflected Cross-Site Scripting (XSS) vulnerability present in the login screen of all WordPress versions. This flaw allows for the execution of XSS without requiring attacker privileges or direct victim interaction once a specially crafted request is delivered. The vulnerability originates from how WordPress processes the username during a failed login attempt, specifically concerning the `sanitize_user()` and `wp_strip_all_tags()` functions, which can mishandle tag-like strings containing whitespace. Under specific circumstances, this XSS vulnerability can be escalated to achieve PHP code execution on the server. This escalation path is more involved, typically requiring a victim who is already logged in as a single-site Administrator to interact with an attacker-controlled page, alongside certain WordPress features and deployment conditions being met. WordPress addressed this issue in version 7.0.3, with fixes also backported to versions as far back as 4.7.
xss2shell - show more detail8CVE-2026-20303
critical 9.9
1
Aug 5, 2026
CVE-2026-20303 identifies a collection of vulnerabilities within Cisco Catalyst SD-WAN Software, primarily stemming from improper input validation issues. These vulnerabilities are grouped under the Common Weakness Enumeration (CWE) CWE-20, representing a change in Cisco's typical disclosure approach where multiple underlying security defects are consolidated under a single CVE based on their common weakness class. This particular grouping encompasses problems such as input validation failures, path traversal, and external path control. The affected software includes Cisco Catalyst SD-WAN deployments across on-premises, Cisco SD-WAN Cloud-Pro, Cisco-managed SD-WAN Cloud, and Cisco SD-WAN for Government environments, regardless of device configuration. Cisco has released software hardening updates to address these internally discovered vulnerabilities, and no workarounds are available.
- show more detail9CVE-2026-20304
critical 9.9
1
Aug 5, 2026
CVE-2026-20304 identifies a set of vulnerabilities within Cisco Catalyst SD-WAN software, stemming from improper access control issues. These flaws are categorized under the Common Weakness Enumeration (CWE) CWE-284. The vulnerabilities were discovered internally by the Cisco Catalyst SD-WAN engineering team during a comprehensive security review. This CVE is part of a broader software hardening release by Cisco, which addresses multiple internally identified security concerns. The improper access control issues could potentially allow an attacker with low-level privileges to bypass security controls.
- show more detail10CVE-2026-64561
high 8.8
1
Aug 4, 2026
CVE-2026-64561, dubbed "Zapscape," is a use-after-free vulnerability found in the Linux kernel's KVM virtualization code, specifically within the x86 shadow memory management unit (MMU). Discovered by researcher Hyunwoo Kim (@v4bel), the flaw stems from an incorrect ordering in page-fault handling. KVM checks the validity of the shadow MMU root before making MMU pages available; however, if shadow-page reclamation invalidates the in-use root during the subsequent page availability process, KVM can proceed to map memory using this now-stale root. This leads to the creation of invalid child shadow pages that are still added to the active MMU page list, violating KVM MMU invariants. Under specific conditions, such as when nested virtualization is enabled and an attacker has kernel-level control within a KVM guest, this vulnerability can be exploited to achieve a guest-to-host escape, allowing the attacker to execute code with root privileges on the host system. A public proof-of-concept exploit exists for Zapscape, which affects Linux kernels from version 5.9 onward.
- show more detail
Hype score
8
·
medium 4.0
Valhall GPU Kernel DriverArm 5th Gen GPU Architecture Kernel Driver