CVE-2026-60137 is trending. Hype score 7, currently #8 on cvemon. WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a… https://cvemon.intruder.io/cves/CVE-2026-60137
cvemon
@cvemon.bsky.social
Trending CVEs from the last 24 hours, ranked by how much noise they're making. Our security team weighs in on whether the panic is justified. Free, from the team at www.intruder.io. cve + monitoring = cvemon đź’›
CVE-2026-63030 is trending. Hype score 7, currently #6 on cvemon. WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection… https://cvemon.intruder.io/cves/CVE-2026-63030
CVE-2026-88779 is trending. Hype score 11, currently #4 on cvemon. Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before… https://cvemon.intruder.io/cves/CVE-2026-88779
CVE-2026-96940 is trending. Hype score 7, currently #6 on cvemon. Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. https://cvemon.intruder.io/cves/CVE-2026-96940
CVE-2026-100520 is trending. Hype score 8, currently #6 on cvemon. Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside… https://cvemon.intruder.io/cves/CVE-2026-100520
CVE-2026-40281 is trending. Hype score 8, currently #4 on cvemon. Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves… https://cvemon.intruder.io/cves/CVE-2026-40281
CVE-2025-4427 is trending. Hype score 4, currently #8 on cvemon. An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API. https://cvemon.intruder.io/cves/CVE-2025-4427
CVE-2026-102489 is trending. Hype score 7, currently #4 on cvemon. Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version… https://cvemon.intruder.io/cves/CVE-2026-102489
CVE-2026-102490 is trending. Hype score 7, currently #3 on cvemon. All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. https://cvemon.intruder.io/cves/CVE-2026-102490
CVE-2026-104286 is trending. Hype score 3, currently #9 on cvemon. An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail… https://cvemon.intruder.io/cves/CVE-2026-104286
CVE-2024-58388 is trending. Hype score 5, currently #6 on cvemon. Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by… https://cvemon.intruder.io/cves/CVE-2024-58388
CVE-2026-86131 is trending. Hype score 2, currently #9 on cvemon. A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary… https://cvemon.intruder.io/cves/CVE-2026-86131
CVE-2026-63692 is trending. Hype score 4, currently #6 on cvemon. Currently trending CVE - Hype Score: 4 https://cvemon.intruder.io/cves/CVE-2026-63692
CVE-2026-63688 is trending. Hype score 4, currently #5 on cvemon. Currently trending CVE - Hype Score: 4 https://cvemon.intruder.io/cves/CVE-2026-63688
CVE-2026-1731 is trending. Hype score 3, currently #8 on cvemon. BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending… https://cvemon.intruder.io/cves/CVE-2026-1731
CVE-2026-76504 is trending. Hype score 3, currently #7 on cvemon. A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with… https://cvemon.intruder.io/cves/CVE-2026-76504
CVE-2025-14564 is trending. Hype score 3, currently #7 on cvemon. The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient… https://cvemon.intruder.io/cves/CVE-2025-14564
CVE-2026-86950 is trending. Hype score 2, currently #10 on cvemon. An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a… https://cvemon.intruder.io/cves/CVE-2026-86950
CVE-2026-96760 is trending. Hype score 3, currently #9 on cvemon. Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns… https://cvemon.intruder.io/cves/CVE-2026-96760
CVE-2026-28802 is trending. Hype score 3, currently #8 on cvemon. Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg:… https://cvemon.intruder.io/cves/CVE-2026-28802
CVE-2026-27962 is trending. Hype score 3, currently #7 on cvemon. Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an… https://cvemon.intruder.io/cves/CVE-2026-27962
CVE-2026-101043 is trending. Hype score 3, currently #7 on cvemon. pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a… https://cvemon.intruder.io/cves/CVE-2026-101043
CVE-2026-102676 is trending. Hype score 8, currently #6 on cvemon. Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview>… https://cvemon.intruder.io/cves/CVE-2026-102676
CVE-2026-61500 is trending. Hype score 8, currently #5 on cvemon. Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to… https://cvemon.intruder.io/cves/CVE-2026-61500
CVE-2023-3519 is trending. Hype score 14, currently #3 on cvemon. Unauthenticated remote code execution https://cvemon.intruder.io/cves/CVE-2023-3519
CVE-2026-14281 is trending. Hype score 14, currently #7 on cvemon. The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and… https://cvemon.intruder.io/cves/CVE-2026-14281
CVE-2026-88775 is trending. Hype score 17, currently #6 on cvemon. Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before… https://cvemon.intruder.io/cves/CVE-2026-88775
CVE-2026-88776 is trending. Hype score 16, currently #7 on cvemon. Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37… https://cvemon.intruder.io/cves/CVE-2026-88776
CVE-2026-88774 is trending. Hype score 14, currently #7 on cvemon. Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS… https://cvemon.intruder.io/cves/CVE-2026-88774
CVE-2026-88773 is trending. Hype score 13, currently #7 on cvemon. Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before… https://cvemon.intruder.io/cves/CVE-2026-88773