Vulnerabilities

Summary — last 7 days

New vulnerabilities2,886▲ 263 vs. last week
Critical / high1,344▼ 85 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
–

403,895 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.3)0.10%—HeymAI10/5/202610/5/2026
Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. Attackers can trigger anonymous workflows with forged headers so reviewer notifications point to attacker domains,…
DeferredMedium (5.5)0.38%—Casbin CasdoorAI10/5/202610/5/2026
A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was…
DeferredMedium (5.3)0.20%—Arraytics WP Event SolutionAI10/5/202610/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25.
DeferredMedium (5.3)0.18%—Arraytics WP Event SolutionAI10/5/202610/6/2026
Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25.
DeferredMedium (5.3)0.18%—Wpmanageninja Fluent Forms PROAI10/5/202610/6/2026
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
Awaiting AnalysisMedium (5.7)0.25%——10/5/202610/6/2026
The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent.
Awaiting AnalysisMedium (5.3)0.23%—ZabbixAI10/5/202610/6/2026
The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
Awaiting AnalysisMedium (6.9)0.20%—Zabbix ServerAIZabbix ProxyAI10/5/202610/6/2026
Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
Awaiting AnalysisMedium (5.1)0.16%——10/5/202610/6/2026
Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
Awaiting AnalysisLow (2.3)0.23%—Zabbix ServerAIZabbix ProxyAI10/5/202610/6/2026
The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
Awaiting AnalysisMedium (6.9)0.24%—Zabbix ServerAI10/5/202610/6/2026
The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
DeferredMedium (4.3)0.15%—Deepak Anand WP Dummy Content GeneratorAI10/5/202610/6/2026
Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0.
DeferredLow (2.1)0.44%—Feelec-yishu Feelcrm-osAI10/5/202610/6/2026
A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The…
DeferredMedium (5.5)0.47%—Feelec-yishu Feelcrm-osAI10/5/202610/7/2026
A vulnerability was determined in feelec-yishu feelcrm-os 1.0.0. This affects an unknown part of the file App/Feelcrm/Index/Controller/GoogleController.class.php of the component getCurlData Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the…
DeferredLow (2)0.33%—Feelec-yishu Feelcrm-osAI10/5/202610/6/2026
A vulnerability was found in feelec-yishu feelcrm-os 1.0.0. Affected by this issue is the function htmlspecialchars_decode of the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php of the component Create Customer Endpoint. Performing a manipulation of the argument customer_form[remark] results in cross site…
Awaiting AnalysisMedium (6.6)0.25%—QT FOR McusAI10/5/202610/6/2026
In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values. The check fails and reports an error, and the default error handler halts the…
DeferredLow (2.1)0.44%—Feelec-yishu Feelcrm-osAI10/5/202610/6/2026
A vulnerability has been found in feelec-yishu feelcrm-os 1.0.0. Affected by this vulnerability is the function IndexController::index of the file App/ThinkPHP/Common/functions.php of the component Crm Endpoint. Such manipulation of the argument redirect_url leads to cross site scripting. The attack may be performed…
DeferredLow (2.1)0.32%—Feelec-yishu Feelcrm-osAI10/5/202610/6/2026
A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation of the argument groups[] causes sql injection. The attack is possible to be carried out remotely.…
DeferredLow (2.1)0.35%—Totolink A3002muAI10/5/202610/7/2026
A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation of the argument filename results in path traversal. The attack can be executed remotely. The exploit is now public and…
DeferredCritical (9.3)0.64%—Totolink A3002muAI10/5/202610/6/2026
A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is…
DeferredMedium (5.3)0.19%—Villatheme CurcyAI10/5/202610/6/2026
Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.
DeferredMedium (5.4)0.17%—Brainstormforce Astra SitesAI10/5/202610/6/2026
Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: from n/a through 4.7.7.
Awaiting AnalysisHigh (7.8)0.11%—Zephyr RtosAI10/5/202610/6/2026
The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c_ccc_target_payload carries its own data…
Awaiting AnalysisHigh (8.4)0.10%—NXP ZephyrAI10/5/202610/6/2026
The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data->results_length and used it in mcux_gau_adc_read_samples() as the…
DeferredCritical (9.3)0.78%—Totolink A3002muAI10/5/202610/6/2026
A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to…