Vulnerabilities

Summary — last 7 days

New vulnerabilities2,743▼ 119 vs. last week
Critical / high1,267▼ 261 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 186 vs. last week
–

59 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.8)0.40%—VictoriametricsAI8/20/20269/18/2026
VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/backup/fslocal/fslocal.go to write restored data below storageDataPath. An attacker…
DeferredLow (2.9)0.75%—VictoriametricsAI8/15/20268/20/2026
A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction of excessive authentication attempts. The attack is possible to be carried out…
AnalyzedMedium (6.8)0.46%—Redhat Cost Management Metrics Operator7/30/20268/12/2026
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this…
AnalyzedHigh (7.6)0.32%—Redhat Cost Management Metrics Operator7/30/20268/12/2026
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL,…
AnalyzedMedium (6.8)0.39%—Redhat Cost Management Metrics Operator7/30/20268/17/2026
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent…
AnalyzedMedium (6.5)0.40%—Pevans Metrics\6/10/20266/23/2026
Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::SignalFx which extends Metrics::Any::Adapter::Statsd, which has a…
AnalyzedCritical (9.1)0.55%—Pevans Metrics\6/10/20266/24/2026
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics::Any::Adapter::DogStatsd which extends Metrics::Any::Adapter::Statsd, which has…
AnalyzedHigh (8.2)0.50%—Pevans Metrics\6/10/20266/24/2026
Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics, separated by newlines, to be sent per packet. The send method does not validate the contents of the metric names or values. If the names have newlines and…
Awaiting AnalysisCritical (9.2)0.31%—AMD Device Metrics ExporterAI5/15/20266/17/2026
Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability
DeferredMedium (5.3)0.52%—ExactmetricsAI4/24/20268/14/2026
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin…
DeferredHigh (7.2)1.00%—ExactmetricsAI4/23/20266/17/2026
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due to the reports page exposing the 'onboarding_key' transient to any user with the…
DeferredMedium (5.4)0.28%—TextmetricsAI3/13/20266/17/2026
Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Textmetrics: from n/a through <= 3.6.4.
DeferredHigh (8.8)0.39%—ExactmetricsAI3/11/20266/17/2026
The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due to the `update_settings()` function accepting arbitrary plugin setting names without a whitelist of allowed settings. This makes it possible for authenticated…
DeferredHigh (8.8)0.64%—ExactmetricsAI3/11/20266/17/2026
The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is due to the `store_settings()` method in the `ExactMetrics_Onboarding` class accepting a user-supplied `triggered_by` parameter that is used instead of the…
DeferredMedium (4.3)0.24%—TextmetricsAI1/23/20266/17/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Israpil Textmetrics webtexttool allows Code Injection.This issue affects Textmetrics: from n/a through <= 3.6.5.
DeferredLow (2.7)0.34%—VictoriametricsAI11/25/20256/17/2026
VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and from 1.123.0 to before 1.129.1, affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits…
AnalyzedCritical (10)0.74%—Radiometrics Vizair11/4/20256/17/2026
Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access and API requests. Attackers can modify configurations without authentication, potentially manipulating active runway settings and misleading air traffic control (ATC) and pilots. Additionally,…
AnalyzedCritical (10)0.77%—Radiometrics Vizair11/4/20256/17/2026
Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without authentication. Once inside, the attacker can modify critical weather parameters such as wind shear alerts, inversion depth, and CAPE values, which are essential for accurate weather forecasting and…
AnalyzedCritical (10)0.66%—Radiometrics Vizair11/4/20256/17/2026
Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration file. This allows attackers to remotely alter weather data and configurations, automate attacks against multiple instances, and extract sensitive meteorological data, which could potentially…
DeferredHigh (8.8)0.42%—SEO MetricsAI8/2/20256/17/2026
The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function in all versions up to, and including, 1.0.15. Because the AJAX action only verifies a…
DeferredMedium (6)0.22%—Akka-cluster-metricsAI6/28/20256/17/2026
In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.
ModifiedMedium (4.8)0.23%—Textmetrics4/22/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics webtexttool allows Stored XSS.This issue affects Textmetrics: from n/a through <= 3.6.2.
DeferredMedium (5.4)0.53%—TextmetricsAI3/27/20256/17/2026
Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Textmetrics: from n/a through <= 3.6.1.
DeferredMedium (5.4)0.31%—Exactmetrics Google Analytics Dashboard FOR WPAI1/24/20256/17/2026
Missing Authorization vulnerability in Syed Balkhi ExactMetrics google-analytics-dashboard-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ExactMetrics: from n/a through <= 8.1.0.
AnalyzedHigh (7.5)0.33%—Loway Queuemetrics9/8/20246/17/2026
Loway - CWE-204: Observable Response Discrepancy
Orbitaley — Vulnerabilities