Posts of last 24 hours
Currently trending CVE - Hype Score: 11 - Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
https://cvemon.intruder.io/cves/CVE-2026-42980
Currently trending CVE - Hype Score: 15 - A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a ...
https://cvemon.intruder.io/cves/CVE-2026-42533
Currently trending CVE - Hype Score: 17 - In the Linux kernel, the following vulnerability has been resolved:
rtmutex: Use waiter::task instead of current in remove_waiter()
remove_waiter() is used by the slowlock paths, but it is also used for
proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked ...
https://cvemon.intruder.io/cves/CVE-2026-43499
Currently trending CVE - Hype Score: 35 - WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
https://cvemon.intruder.io/cves/CVE-2026-60137
Currently trending CVE - Hype Score: 41 - WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
https://cvemon.intruder.io/cves/CVE-2026-63030
Currently trending CVE - Hype Score: 5 - A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
https://cvemon.intruder.io/cves/CVE-2026-15409
Currently trending CVE - Hype Score: 6 - Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
https://cvemon.intruder.io/cves/CVE-2026-56164
Currently trending CVE - Hype Score: 5 - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
https://cvemon.intruder.io/cves/CVE-2026-45659
A vulnerability was found in RVC-Boss GPT-SoVITS up to 20250606v2pro. It has been classified as critical. The affected element is the function ASR/slice/denoise/uvr5 of the file webui.py of the component WebUI. This manipulation of the argument path causes os command injection.
The identification of this vulnerability is CVE-2026-63766. It is possible to initiate the attack remotely. There is no exploit available.
https://vuldb.com/vuln/380750