Vulnerabilities
Summary — last 7 days
New vulnerabilities2,833▲ 192 vs. last week
Critical / high1,319▼ 117 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)234▲ 220 vs. last week
70 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (4.3) | 0.29% | — | Wpdeveloper BetterlinksAI | 8/25/2026 | 8/26/2026 | The BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Deferred | Low (2.1) | 0.35% | — | Spacex Starlink Router GEN 3AI | 8/16/2026 | 8/20/2026 | A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the… | |
| Deferred | Low (3.5) | 0.30% | — | Kerlink Wirnet Istation 868AIKerlink KerosAI | 7/16/2026 | 7/17/2026 | Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs component. | |
| Deferred | Medium (5.7) | 0.30% | — | Kerlink Wirnet Istation 868AI | 7/16/2026 | 7/17/2026 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component. | |
| Deferred | High (7.3) | 0.85% | — | Kerlink Wirnet Istation 868AIKerlink KerosAI | 7/16/2026 | 7/17/2026 | Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the SNMP update mechanism. | |
| Deferred | Medium (4.3) | 0.31% | — | Kerlink Wirnet Istation 868AI | 7/16/2026 | 7/17/2026 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a boardID and revisionID components | |
| Deferred | Medium (6.1) | 0.26% | — | SEO Links InterlinkingAI | 1/28/2026 | 6/17/2026 | The SEO Links Interlinking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_error' parameter in all versions up to, and including, 1.7.9.9.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Deferred | Medium (4.2) | 0.17% | 💥 PoC | Spacex Starlink DishAI | 12/11/2025 | 10/7/2026 | SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN gRPC requests, aka MARMALADE 2. The cross-origin policy can be bypassed by omitting a Referer header. In some cases, an attacker's ability to read tilt, rotation, and elevation data… | |
| Analyzed | Medium (5.3) | 1.2% | — | Kerlink Keros | 12/1/2025 | 6/17/2026 | Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP packets. This allows an attacker to bypass the firewall and access UDP-based services that would otherwise be protected. | |
| Analyzed | High (7.4) | 0.18% | — | Kerlink Keros | 12/1/2025 | 6/17/2026 | Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS support. This lack of transport layer security allows a man-in-the-middle attacker to intercept and modify traffic between the client and the device. | |
| Analyzed | High (8.1) | 0.52% | — | Kerlink Keros | 12/1/2025 | 9/26/2026 | The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall. | |
| Deferred | Low (2.1) | 0.34% | — | Allstarlink SupermonAIAllstarlink Allmon2AI | 10/5/2025 | 10/8/2026 | A security vulnerability has been detected in AllStarLink Supermon up to 6.2. This vulnerability affects unknown code of the component AllMon2. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early… | |
| Deferred | High (8.7) | 0.40% | — | Airlink DaemonAIDockerAI | 8/25/2025 | 6/17/2026 | Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel. In version 1.0.0, an attacker with access to the affected container can create symbolic links inside the mounted directory (/app/data). Because the container bind-mounts an arbitrary host path, these… | |
| Analyzed | High (8.8) | 0.41% | — | Carlinkit Autokit | 4/23/2025 | 6/17/2026 | CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analyzed | High (8) | 0.25% | — | Carlinkit Autokit | 4/23/2025 | 6/17/2026 | CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Although authentication is required to exploit this vulnerability,… | |
| Analyzed | Medium (6.8) | 0.21% | — | Carlinkit Autokit | 4/23/2025 | 6/17/2026 | CarlinKit CPC200-CCPA Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit this vulnerability. The specific… | |
| Analyzed | High (7.8) | 0.19% | — | Carlinkit Autokit | 4/23/2025 | 6/17/2026 | CarlinKit CPC200-CCPA Missing Root of Trust Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of CarlinKit CPC200-CCPA devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Deferred | Medium (6.5) | 0.22% | — | Daniel Floeter Hyperlink Group BlockAI | 4/1/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block hyperlink-group-block allows DOM-Based XSS.This issue affects Hyperlink Group Block: from n/a through <= 2.0.1. | |
| Modified | High (8.8) | 0.37% | — | Wpdeveloper Betterlinks | 1/2/2025 | 6/17/2026 | Missing Authorization vulnerability in WPDeveloper BetterLinks betterlinks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterLinks: from n/a through <= 1.6.0. | |
| Modified | High (7.2) | 0.46% | — | Wpdeveloper Betterlinks | 11/4/2024 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks betterlinks allows SQL Injection.This issue affects BetterLinks: from n/a through <= 2.1.7. | |
| Deferred | Medium (6.5) | 0.27% | — | Daniel Floeter Hyperlink Group BlockAI | 10/17/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block hyperlink-group-block allows Stored XSS.This issue affects Hyperlink Group Block: from n/a through <= 1.17.5. | |
| Deferred | Medium (6.8) | 0.33% | 💥 PoC | Spacex Starlink Wifi Router GEN 2AI | 4/5/2024 | 6/17/2026 | SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page. | |
| Deferred | High (8.8) | 0.54% | 💥 PoC | Spacex Starlink Wifi Router GEN 2AISpacex Starlink DishAI | 4/5/2024 | 6/17/2026 | SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a reboot) via a DNS Rebinding attack. | |
| Modified | Critical (9.8) | 70% | — | Interlink Psg-5124 Firmware | 6/22/2023 | 6/17/2026 | An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted GET request. | |
| Modified | High (7.2) | 5.2% | 💥 PoC | Eparks Fiberlink 210 Firmware | 5/23/2023 | 6/17/2026 | An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/admin/formPing target_addr parameter. |