Vulnerabilities
Summary — last 7 days
New vulnerabilities2,831▲ 194 vs. last week
Critical / high1,317▼ 115 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)234▲ 220 vs. last week
403,854 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.1) | 0.38% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email… | |
| Deferred | Critical (9.6) | 0.32% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another… | |
| Deferred | Critical (9.9) | 0.35% | — | PlaneAI | 10/5/2026 | 10/7/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original… | |
| Deferred | High (7.4) | 0.45% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding… | |
| Deferred | High (8.1) | 0.29% | — | PlaneAI | 10/5/2026 | 10/6/2026 | Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does… | |
| Deferred | Medium (5.5) | 0.33% | — | Anisha Online Appointment Booking SystemAI | 10/5/2026 | 10/6/2026 | A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible… | |
| Deferred | Medium (5.5) | 0.33% | — | Onetwothreeneth HospitalmanagementsystemAI | 10/5/2026 | 10/6/2026 | A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the function get of the file print.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Awaiting Analysis | Low (2.5) | 0.22% | — | CupsAI | 10/5/2026 | 10/7/2026 | An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as… | |
| Analyzed | High (8.8) | 0.68% | — | Apache Struts | 10/5/2026 | 10/8/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the application-wide text provider is used by concurrently served requests without isolation,… | |
| Analyzed | Medium (6.5) | 0.69% | — | Apache Struts | 10/5/2026 | 10/8/2026 | Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in proportion to its size, exhausting the Java heap and denying service to… | |
| Analyzed | High (7.5) | 0.95% | — | Apache Struts | 10/5/2026 | 10/8/2026 | Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the… | |
| Analyzed | Critical (9.8) | 1.2% | — | Apache Struts | 10/5/2026 | 10/8/2026 | Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts… | |
| Deferred | Critical (9.3) | 0.25% | — | Wp-base WP Base BookingAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0. | |
| Deferred | High (7.2) | 0.40% | — | Rymera WEB CO WOO Product Feed PROAI | 10/5/2026 | 10/6/2026 | Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.5.7. | |
| Deferred | High (7.5) | 0.32% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 10/5/2026 | 10/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.24. | |
| Deferred | Medium (6.5) | 0.23% | — | Ayecode UserswpAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74. | |
| Deferred | Medium (6.5) | 0.20% | — | Wpusermanager WP User ManagerAI | 10/5/2026 | 10/6/2026 | Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20. | |
| Deferred | Medium (6.5) | 0.25% | — | Villatheme LookzyAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in VillaTheme Lookzy woo-lookbook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lookzy: from n/a through 1.1.14. | |
| Deferred | High (7.1) | 0.19% | — | Villatheme Photo Reviews FOR WoocommerceAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30. | |
| Deferred | Medium (6.5) | 0.17% | — | Webfulcreations RepairbuddyAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Stored XSS.This issue affects RepairBuddy: from n/a through 4.1225. | |
| Awaiting Analysis | Medium (6.8) | 0.11% | — | Moby BuildkitAI | 10/5/2026 | 10/6/2026 | The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds… | |
| Awaiting Analysis | Medium (6.9) | 0.13% | — | Moby BuildkitAI | 10/5/2026 | 10/6/2026 | A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. | |
| Awaiting Analysis | Medium (6) | 0.11% | — | Moby BuildkitAI | 10/5/2026 | 10/6/2026 | BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access. | |
| Awaiting Analysis | Medium (5.7) | 0.09% | — | Moby BuildkitAI | 10/5/2026 | 10/6/2026 | A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic. | |
| Awaiting Analysis | High (7.5) | 0.17% | — | Moby BuildkitAI | 10/5/2026 | 10/6/2026 | A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent… |