Vulnerabilities
Summary — last 7 days
New vulnerabilities2,856▲ 218 vs. last week
Critical / high1,330▼ 103 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
403,868 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.5) | 0.26% | — | Onetwothreeneth Hospitalmanagement SystemAI | 10/5/2026 | 10/7/2026 | A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this vulnerability is an unknown functionality of the file transaction_details.php. Executing a manipulation of the argument transaction_id can lead to sql injection. The attack may be… | |
| Deferred | Medium (5.5) | 0.25% | — | Union HospitalmanagmentsystemAI | 10/5/2026 | 10/6/2026 | A vulnerability was found in UNION HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected is an unknown function of the file patient_info.php. Performing a manipulation of the argument patient_id results in sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Deferred | High (8.7) | 0.36% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML… | |
| Deferred | High (8.2) | 0.29% | — | PlaneAI | 10/5/2026 | 10/7/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accepts an invitation based only on a submitted email address. When a pending… | |
| Deferred | High (7.7) | 0.30% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project member can make the server fetch attacker-selected internal targets,… | |
| Deferred | High (8.7) | 0.25% | — | PlaneAI | 10/5/2026 | 10/6/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane validates GITEA_HOST only for its URL scheme and does not reject hosts that resolve to private or internal IP addresses. The four outbound requests in the Gitea OAuth flow are derived from this unvalidated host and do not call validate_url(). In… | |
| Deferred | High (7.1) | 0.26% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v2.py were remediated for two cross-tenant asset IDORs, CVE-2026-27705 and CVE-2026-46558. Those fixes added a membership check and project_id and workspace__slug scoping to the asset endpoints… | |
| Deferred | High (8.1) | 0.50% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in with existing credentials. Successful authentication silently changes is_active back to True, reactivating the account without notifying the administrator. This issue… | |
| Deferred | High (7.6) | 0.27% | — | PlaneAI | 10/5/2026 | 10/7/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is created in apps/api/plane/app/serializers/webhook.py. The delivery task in apps/api/plane/bgtasks/webhook_task.py performs a separate DNS resolution when sending the… | |
| Deferred | High (8.5) | 0.35% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller's workspace, allowing cross-workspace asset duplication. WorkspaceFileAssetEndpoint and the legacy FileAssetEndpoint omit workspace authorization, allowing authenticated… | |
| Deferred | Medium (6.1) | 0.51% | 💥 PoC | FacturascriptsAI | 10/5/2026 | 10/6/2026 | FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the… | |
| Awaiting Analysis | Medium (4.2) | 0.29% | — | Redhat QuayAI | 10/5/2026 | 10/6/2026 | A flaw was found in Quay. A remote attacker could trick a user into logging in through a crafted link, resulting in cross-site scripting (XSS). Because the application does not validate the redirect destination before navigating, this flaw allows the execution of arbitrary script in the context of the victim's… | |
| Awaiting Analysis | Medium (5.4) | 0.22% | — | Redhat QuayAI | 10/5/2026 | 10/6/2026 | A flaw was found in Quay. A cross-site scripting (XSS) vulnerability in the OAuth callback handler allows a remote attacker to execute arbitrary JavaScript code within a user's browser session. By tricking a logged-in user into visiting a specially crafted link, an attacker can exploit improper input sanitization to… | |
| Awaiting Analysis | High (8.8) | 0.42% | — | Redhat Hypershift OperatorAI | 10/5/2026 | 10/7/2026 | A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability… | |
| Deferred | High (7.1) | 0.15% | — | Adsplugin AdsmonetizerAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Fernandez Adsmonetizer adsensei-b30 allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.2.4. | |
| Awaiting Analysis | High (8.4) | 0.25% | — | Eclipse CHEAI | 10/5/2026 | 10/6/2026 | In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory/resolver` endpoints pass an attacker-controlled URL to `URLFetcher.fetch()`, which calls `new URL(url).openConnection()` with no scheme or host allow-list and returns the response body to the caller. Any authenticated Che user… | |
| Awaiting Analysis | Medium (4.9) | 0.22% | — | VelociraptorAI | 10/5/2026 | 10/6/2026 | Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access. | |
| Deferred | High (8.4) | 0.22% | — | Auto-changelogAI | 10/5/2026 | 10/6/2026 | auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over… | |
| Deferred | Medium (5.5) | 0.26% | — | Onetwothreeneth Hospital Management SystemAI | 10/5/2026 | 10/6/2026 | A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This impacts an unknown function of the file php/controller.php. Such manipulation of the argument transaction_idS leads to sql injection. The attack can be executed remotely. The exploit has been… | |
| Deferred | Medium (5.5) | 0.29% | — | Onetwothreeneth Hospital Management SystemAI | 10/5/2026 | 10/6/2026 | A flaw has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function update_subaccount of the file php/controller.php of the component Account Administration. This manipulation of the argument user_id causes improper authorization. Remote… | |
| Deferred | High (8.1) | 0.27% | — | PlaneAI | 10/5/2026 | 10/6/2026 | Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs account creation without an atomic transaction, row lock, uniqueness guard, or… | |
| Deferred | Medium (6.5) | 0.27% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can add issues from any workspace to a cycle they control. If a victim issue is already assigned to a… | |
| Deferred | High (8.7) | 0.31% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace-member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace slug, even when the caller is not a workspace member. The endpoint also… | |
| Deferred | Medium (5.4) | 0.18% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/ accept body- or URL-supplied issue IDs and operate on them without checking that the IDs belong to the caller's workspace and project. The permission decorator on each… | |
| Deferred | High (8.7) | 0.25% | — | PlaneAI | 10/5/2026 | 10/6/2026 | Plane is an open-source project management tool. Prior to 1.4.0, two endpoint families fail to verify that nested resource identifiers belong to the workspace and project named in the URL. An authenticated user can read or modify estimates from another workspace through PATCH… |