Vulnerabilities
Summary — last 7 days
New vulnerabilities3,145▲ 571 vs. last week
Critical / high1,455▲ 53 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)301▲ 287 vs. last week
404,200 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.1) | 0.17% | — | Thimpress LearnpressAI | 10/5/2026 | 10/7/2026 | LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that… | |
| Deferred | Low (2.1) | 0.40% | — | TallcmsAI | 10/5/2026 | 10/7/2026 | A vulnerability was determined in TallCMS up to 4.8.0. This affects an unknown function of the file packages/tallcms/cms/src/Filament/Pages/ThemeManager.php of the component PluginManager. Executing a manipulation can lead to code injection. The attack can be launched remotely. The exploit has been publicly disclosed… | |
| Deferred | High (8.7) | 0.25% | — | PlaneAI | 10/5/2026 | 10/5/2026 | Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0. | |
| Deferred | High (7.5) | 0.28% | — | Insumermodel Mppx Condition GateAIInsumermodel Mppx Token GateAI | 10/5/2026 | 10/6/2026 | mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain… | |
| Deferred | High (7.2) | 0.42% | — | Kunstmaan CMSAI | 10/5/2026 | 10/7/2026 | Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend… | |
| Undergoing Analysis | Medium (6.9) | 0.26% | — | Joomlafry TF ContentAI | 10/5/2026 | 10/6/2026 | Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the… | |
| Undergoing Analysis | Medium (5.3) | 0.15% | — | Svenbluege.de Event GalleryAI | 10/5/2026 | 10/6/2026 | Joomla Extension - svenbluege.de - Cross-site scripting and open redirect on the share mini page in Event Gallery extension < 6.6.0 - The page a shared image link opens (the share mini page of the front end) can link the article the image was shared from when the option "Share article links" is on. It took the address… | |
| Undergoing Analysis | Medium (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 10/5/2026 | 10/6/2026 | Joomla Extension - svenbluege.de - Cross-site request forgery of list tasks of the backend in Event Gallery extension < 6.6.0 - Eight tasks which the buttons of the back-end lists call did not check the form token: setting the default payment method, shipping method, image type set, order status and watermark; putting… | |
| Undergoing Analysis | High (8.7) | 0.38% | — | Phoca CartAI | 10/5/2026 | 10/6/2026 | Joomla Extension - phoca.cz - Authorisation bypass through user-controlled key (IDOR) in Order View in Phoca Cart 5.0.0 - 6.1.8 - Phoca Cart's order-file download endpoint does not verify the download tokens it asks for. The d (download token) and o (order token) parameters are checked for non-emptiness only — they… | |
| Undergoing Analysis | Critical (9.3) | 0.28% | 💥 PoC | Ordasoft Joomla CCKAI | 10/5/2026 | 10/6/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector. | |
| Undergoing Analysis | Medium (5.3) | 0.29% | — | Joomshaper SP Page Builder PROAI | 10/5/2026 | 10/6/2026 | Joomla Extension - joomshaper.com - Reflected XSS in the Dynamic Content Filter addon in SP Page Builder Pro 3.0.0 - 5.6.1p2 - The slider minimum and maximum values are taken from the dc_filter_<fieldId> request parameter, split on the delimiter "l-r", HTML-escaped inside the data-value attribute, and then echoed… | |
| Deferred | Medium (6.5) | 0.38% | — | K6 MCP ServerAI | 10/5/2026 | 10/6/2026 | A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of any file readable by the user running the server, including SSH keys and cloud credentials in that user's home directory (path traversal). The working-directory… | |
| Deferred | High (7.5) | 0.57% | — | WookteamAI | 10/5/2026 | 10/6/2026 | WookTeam v1.6.6 and before is vulnerable to a Directory Traversal. The project task export endpoint /api/project/task/export downloads an arbitrary file from the server when the data parameter is supplied with a crafted JSON payload. The file value inside the JSON is concatenated directly into storage_path($file)… | |
| Deferred | High (7.5) | 0.69% | — | UnimallAI | 10/5/2026 | 10/6/2026 | Unimall v4 is vulnerable to Directory Traversal in FileUploadController.local(). This allows an attacker to execute arbitrary code. | |
| Awaiting Analysis | Critical (9.8) | 0.36% | — | Dromara NorthstarAI | 10/5/2026 | 10/6/2026 | Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/**, so /h2-console is exposed with no authentication and the embedded H2 DB uses default sa / empty password. Any network-reachable attacker can run arbitrary system commands via… | |
| Awaiting Analysis | Critical (9) | 0.27% | — | HPE Integrated Lights OUT 7AI | 10/5/2026 | 10/6/2026 | A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware. | |
| Deferred | Medium (5.3) | 0.18% | — | KIT FOR WoocommerceAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kit (formerly ConvertKit) for WooCommerce: from n/a through 2.2.0. | |
| Awaiting Analysis | High (8.8) | 0.26% | — | Progress Sitefinity Nextjs SDKAI | 10/5/2026 | 10/6/2026 | CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information. | |
| Awaiting Analysis | High (7.9) | 0.06% | — | Progress Telerik Fiddler ClassicAI | 10/5/2026 | 10/6/2026 | In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose… | |
| Awaiting Analysis | Medium (6.6) | 0.06% | — | Progress Fiddler ClassicAI | 10/5/2026 | 10/6/2026 | In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the certificate to a temporary file in a… | |
| Awaiting Analysis | Low (3.6) | 0.09% | — | Progress Telerik Fiddler ClassicAI | 10/5/2026 | 10/6/2026 | In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames… | |
| Awaiting Analysis | Medium (6.3) | 0.09% | — | Progress Fiddler ClassicAI | 10/5/2026 | 10/6/2026 | In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting values are forwarded verbatim to the origin server, while Fiddler frames the request… | |
| Deferred | Low (2) | 0.25% | — | Django HaystackAI | 10/5/2026 | 10/6/2026 | A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of the argument result_class leads to improper neutralization of directives in dynamically… | |
| Deferred | High (8.5) | 0.14% | 💥 PoC | Libreoffice CalcAI | 10/5/2026 | 10/6/2026 | LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has… | |
| Deferred | Medium (6.7) | 0.12% | — | LibreofficeAI | 10/5/2026 | 10/6/2026 | URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not cover every place a document can supply a URL. XForms instance data and… |