Vulnerabilities
Summary — last 7 days
New vulnerabilities3,185▲ 600 vs. last week
Critical / high1,508▲ 101 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
404,210 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.19% | — | Wpmailster WP MailsterAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0. | |
| Deferred | High (8.4) | 0.19% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability. The specific flaw exists within the Configuration → Services → Music on Hold functionality of the web portal… | |
| Deferred | High (8.4) | 0.35% | — | Mitel Mivoice Office 400AI | 10/5/2026 | 10/6/2026 | This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability. The specific flaw exists within the web portal listening on TCP port 443, under Maintenance → File Management → File Browser, which is… | |
| Deferred | High (8.4) | 0.09% | — | Mitel Linux Virtual MachineAI | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object… | |
| Deferred | Low (1.9) | 0.25% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content, resulting in a denial-of-service condition within the web application. The specific flaw exists within the web portal listening on TCP port 443,… | |
| Deferred | Low (1.9) | 0.25% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application. The specific flaw exists within the web portal listening on TCP port 443, under Configuration → Domains, specifically in… | |
| Deferred | Medium (5.5) | 0.31% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory. The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate… | |
| Deferred | High (8.5) | 0.22% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration. The specific flaw exists within the backup restoration mechanism, which fails to properly… | |
| Deferred | High (8.4) | 0.14% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs | |
| Deferred | Medium (4.3) | 0.17% | — | Stellarwp Event TicketsAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0. | |
| Deferred | Medium (6.5) | 0.16% | — | Sonaar MP3 Audio Player FOR Music Radio PodcastAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.14.2. | |
| Deferred | Medium (6.5) | 0.16% | — | Wpchill Final Tiles Grid Gallery LiteAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Stored XSS.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.13. | |
| Deferred | High (7.6) | 0.28% | — | GroundhoggAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Groundhogg groundhogg allows Blind SQL Injection.This issue affects Groundhogg: from n/a through 4.8.3. | |
| Deferred | High (7.1) | 0.10% | — | Blubrry PowerpressAI | 10/5/2026 | 10/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9. | |
| Deferred | Medium (6.5) | 0.16% | — | Stellarwp GivewpAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from n/a through 4.17.0. | |
| Deferred | Medium (4.3) | 0.21% | — | MemberfulAI | 10/5/2026 | 10/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects Memberful - Membership Plugin: from n/a through 1.81.2. | |
| Deferred | Medium (6.5) | 0.16% | — | Bplugins B BlocksAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8. | |
| Deferred | Medium (5.3) | 0.23% | — | Jeroen Peters Name DirectoryAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Name Directory: from n/a through 1.34.2. | |
| Deferred | Medium (6.5) | 0.16% | — | Jeroen Peters Name DirectoryAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Name Directory name-directory allows Stored XSS.This issue affects Name Directory: from n/a through 1.34.2. | |
| Deferred | High (8.5) | 0.26% | — | SirvAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sirv Sirv sirv allows Blind SQL Injection.This issue affects Sirv: from n/a through 8.2.5. | |
| Deferred | Medium (5.3) | 0.23% | — | Blubrry PowerpressAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9. | |
| Deferred | Medium (6.5) | 0.15% | — | Rextheme WP VRAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 9.1.3. | |
| Awaiting Analysis | Medium (5.3) | 0.37% | — | Perforce P4 SearchAI | 10/5/2026 | 10/6/2026 | Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner. | |
| Awaiting Analysis | Medium (5.1) | 0.33% | — | Perforce P4 SearchAI | 10/5/2026 | 10/6/2026 | Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory. | |
| Awaiting Analysis | Critical (9.5) | 0.35% | — | Perforce P4 SearchAI | 10/5/2026 | 10/6/2026 | P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server. |