Vulnerabilities
Summary — last 7 days
New vulnerabilities3,008▲ 385 vs. last week
Critical / high1,453▲ 24 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
404,032 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.8) | 0.46% | — | PlaneAI | 10/5/2026 | 10/7/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only… | |
| Deferred | Critical (9.1) | 0.38% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's… | |
| Deferred | Critical (9.8) | 0.39% | — | PlaneAI | 10/5/2026 | 10/6/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each… | |
| Deferred | Critical (9.1) | 0.38% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email… | |
| Deferred | Critical (9.6) | 0.32% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another… | |
| Deferred | Critical (9.9) | 0.35% | — | PlaneAI | 10/5/2026 | 10/7/2026 | Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original… | |
| Deferred | High (7.4) | 0.45% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding… | |
| Deferred | High (8.1) | 0.29% | — | PlaneAI | 10/5/2026 | 10/6/2026 | Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does… | |
| Deferred | Medium (5.5) | 0.33% | — | Anisha Online Appointment Booking SystemAI | 10/5/2026 | 10/6/2026 | A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible… | |
| Deferred | Medium (5.5) | 0.33% | — | Onetwothreeneth HospitalmanagementsystemAI | 10/5/2026 | 10/6/2026 | A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the function get of the file print.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Awaiting Analysis | Low (2.5) | 0.22% | — | CupsAI | 10/5/2026 | 10/7/2026 | An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as… | |
| Analyzed | High (8.8) | 0.68% | — | Apache Struts | 10/5/2026 | 10/8/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the application-wide text provider is used by concurrently served requests without isolation,… | |
| Analyzed | Medium (6.5) | 0.69% | — | Apache Struts | 10/5/2026 | 10/8/2026 | Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in proportion to its size, exhausting the Java heap and denying service to… | |
| Analyzed | High (7.5) | 0.95% | — | Apache Struts | 10/5/2026 | 10/8/2026 | Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the… | |
| Analyzed | Critical (9.8) | 1.2% | — | Apache Struts | 10/5/2026 | 10/8/2026 | Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts… | |
| Deferred | Critical (9.3) | 0.25% | — | Wp-base WP Base BookingAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0. | |
| Deferred | High (7.2) | 0.40% | — | Rymera WEB CO WOO Product Feed PROAI | 10/5/2026 | 10/6/2026 | Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.5.7. | |
| Deferred | High (7.5) | 0.32% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 10/5/2026 | 10/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.24. | |
| Deferred | Medium (6.5) | 0.23% | — | Ayecode UserswpAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74. | |
| Deferred | Medium (6.5) | 0.20% | — | Wpusermanager WP User ManagerAI | 10/5/2026 | 10/6/2026 | Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20. | |
| Deferred | Medium (6.5) | 0.25% | — | Villatheme LookzyAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in VillaTheme Lookzy woo-lookbook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lookzy: from n/a through 1.1.14. | |
| Deferred | High (7.1) | 0.19% | — | Villatheme Photo Reviews FOR WoocommerceAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30. | |
| Deferred | Medium (6.5) | 0.17% | — | Webfulcreations RepairbuddyAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Stored XSS.This issue affects RepairBuddy: from n/a through 4.1225. | |
| Awaiting Analysis | Medium (6.8) | 0.11% | — | Moby BuildkitAI | 10/5/2026 | 10/6/2026 | The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds… | |
| Awaiting Analysis | Medium (6.9) | 0.13% | — | Moby BuildkitAI | 10/5/2026 | 10/6/2026 | A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. |