Vulnerabilities
Summary — last 7 days
New vulnerabilities2,743▼ 119 vs. last week
Critical / high1,267▼ 261 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 186 vs. last week
59 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.8) | 0.40% | — | VictoriametricsAI | 8/20/2026 | 9/18/2026 | VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/backup/fslocal/fslocal.go to write restored data below storageDataPath. An attacker… | |
| Deferred | Low (2.9) | 0.75% | — | VictoriametricsAI | 8/15/2026 | 8/20/2026 | A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts. The attack is possible to be carried out… | |
| Analyzed | Medium (6.8) | 0.46% | — | Redhat Cost Management Metrics Operator | 7/30/2026 | 8/12/2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this… | |
| Analyzed | High (7.6) | 0.32% | — | Redhat Cost Management Metrics Operator | 7/30/2026 | 8/12/2026 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL,… | |
| Analyzed | Medium (6.8) | 0.39% | — | Redhat Cost Management Metrics Operator | 7/30/2026 | 8/17/2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent… | |
| Analyzed | Medium (6.5) | 0.40% | — | Pevans Metrics\ | 6/10/2026 | 6/23/2026 | Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::Statsd, which has a… | |
| Analyzed | Critical (9.1) | 0.55% | — | Pevans Metrics\ | 6/10/2026 | 6/24/2026 | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has… | |
| Analyzed | High (8.2) | 0.50% | — | Pevans Metrics\ | 6/10/2026 | 6/24/2026 | Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics, separated by newlines, to be sent per packet. The send method does not validate the contents of the metric names or values. If the names have newlines and… | |
| Awaiting Analysis | Critical (9.2) | 0.31% | — | AMD Device Metrics ExporterAI | 5/15/2026 | 6/17/2026 | Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability | |
| Deferred | Medium (5.3) | 0.52% | — | ExactmetricsAI | 4/24/2026 | 8/14/2026 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin… | |
| Deferred | High (7.2) | 1.00% | — | ExactmetricsAI | 4/23/2026 | 6/17/2026 | The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due to the reports page exposing the 'onboarding_key' transient to any user with the… | |
| Deferred | Medium (5.4) | 0.28% | — | TextmetricsAI | 3/13/2026 | 6/17/2026 | Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Textmetrics: from n/a through <= 3.6.4. | |
| Deferred | High (8.8) | 0.39% | — | ExactmetricsAI | 3/11/2026 | 6/17/2026 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due to the `update_settings()` function accepting arbitrary plugin setting names without a whitelist of allowed settings. This makes it possible for authenticated… | |
| Deferred | High (8.8) | 0.64% | — | ExactmetricsAI | 3/11/2026 | 6/17/2026 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is due to the `store_settings()` method in the `ExactMetrics_Onboarding` class accepting a user-supplied `triggered_by` parameter that is used instead of the… | |
| Deferred | Medium (4.3) | 0.24% | — | TextmetricsAI | 1/23/2026 | 6/17/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Israpil Textmetrics webtexttool allows Code Injection.This issue affects Textmetrics: from n/a through <= 3.6.5. | |
| Deferred | Low (2.7) | 0.34% | — | VictoriametricsAI | 11/25/2025 | 6/17/2026 | VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and from 1.123.0 to before 1.129.1, affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits… | |
| Analyzed | Critical (10) | 0.74% | — | Radiometrics Vizair | 11/4/2025 | 6/17/2026 | Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally,… | |
| Analyzed | Critical (10) | 0.77% | — | Radiometrics Vizair | 11/4/2025 | 6/17/2026 | Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without authentication. Once inside, the attacker can modify critical weather parameters such as wind shear alerts, inversion depth, and CAPE values, which are essential for accurate weather forecasting and… | |
| Analyzed | Critical (10) | 0.66% | — | Radiometrics Vizair | 11/4/2025 | 6/17/2026 | Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to remotely alter weather data and configurations, automate attacks against multiple instances, and extract sensitive meteorological data, which could potentially… | |
| Deferred | High (8.8) | 0.42% | — | SEO MetricsAI | 8/2/2025 | 6/17/2026 | The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function in all versions up to, and including, 1.0.15. Because the AJAX action only verifies a… | |
| Deferred | Medium (6) | 0.22% | — | Akka-cluster-metricsAI | 6/28/2025 | 6/17/2026 | In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics. | |
| Modified | Medium (4.8) | 0.23% | — | Textmetrics | 4/22/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics webtexttool allows Stored XSS.This issue affects Textmetrics: from n/a through <= 3.6.2. | |
| Deferred | Medium (5.4) | 0.53% | — | TextmetricsAI | 3/27/2025 | 6/17/2026 | Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Textmetrics: from n/a through <= 3.6.1. | |
| Deferred | Medium (5.4) | 0.31% | — | Exactmetrics Google Analytics Dashboard FOR WPAI | 1/24/2025 | 6/17/2026 | Missing Authorization vulnerability in Syed Balkhi ExactMetrics google-analytics-dashboard-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ExactMetrics: from n/a through <= 8.1.0. | |
| Analyzed | High (7.5) | 0.33% | — | Loway Queuemetrics | 9/8/2024 | 6/17/2026 | Loway - CWE-204: Observable Response Discrepancy |