Vulnerabilities
Summary — last 7 days
New vulnerabilities3,246▲ 702 vs. last week
Critical / high1,521▲ 136 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)235▲ 221 vs. last week
404,318 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.5) | 0.26% | — | Itsourcecode Online Admission SystemAI | 10/5/2026 | 10/6/2026 | A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Deferred | Medium (5.3) | 0.25% | — | VgmstreamAI | 10/5/2026 | 10/6/2026 | A vulnerability was detected in vgmstream up to r2117. Affected by this vulnerability is the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named… | |
| Deferred | Medium (6.5) | 0.13% | — | Nikki Blight QR RedirectorAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikki Blight QR Redirector qr-redirector allows Stored XSS.This issue affects QR Redirector: from n/a through 2.0.5. | |
| Deferred | Medium (5.3) | 0.20% | — | Pixelite Events ManagerAI | 10/5/2026 | 10/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This issue affects Events Manager: from n/a through 7.4.5. | |
| Deferred | Medium (6.5) | 0.24% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 10/5/2026 | 10/6/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Parameter Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Deferred | Medium (4.3) | 0.16% | — | Brandtoss WP Admin AuditAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Brandtoss WP Admin Audit wp-admin-audit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Admin Audit: from n/a through 1.2.17. | |
| Deferred | Medium (6.5) | 0.13% | — | Themepoints Logo ShowcaseAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase logo-showcase allows Stored XSS.This issue affects Logo Showcase: from n/a through 4.0.4. | |
| Deferred | Medium (6.5) | 0.13% | — | Implecode Ecommerce Product CatalogAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Stored XSS.This issue affects eCommerce Product Catalog: from n/a through 3.6.2. | |
| Deferred | Medium (5.3) | 0.19% | — | Wpmailster WP MailsterAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0. | |
| Deferred | High (8.4) | 0.19% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability. The specific flaw exists within the Configuration → Services → Music on Hold functionality of the web portal… | |
| Deferred | High (8.4) | 0.35% | — | Mitel Mivoice Office 400AI | 10/5/2026 | 10/6/2026 | This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability. The specific flaw exists within the web portal listening on TCP port 443, under Maintenance → File Management → File Browser, which is… | |
| Deferred | High (8.4) | 0.09% | — | Mitel Linux Virtual MachineAI | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object… | |
| Deferred | Low (1.9) | 0.25% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content, resulting in a denial-of-service condition within the web application. The specific flaw exists within the web portal listening on TCP port 443,… | |
| Deferred | Low (1.9) | 0.25% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application. The specific flaw exists within the web portal listening on TCP port 443, under Configuration → Domains, specifically in… | |
| Deferred | Medium (5.5) | 0.31% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory. The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate… | |
| Deferred | High (8.5) | 0.22% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration. The specific flaw exists within the backup restoration mechanism, which fails to properly… | |
| Deferred | High (8.4) | 0.14% | — | — | 10/5/2026 | 10/6/2026 | DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs | |
| Deferred | Medium (4.3) | 0.17% | — | Stellarwp Event TicketsAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0. | |
| Deferred | Medium (6.5) | 0.16% | — | Sonaar MP3 Audio Player FOR Music Radio PodcastAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.14.2. | |
| Deferred | Medium (6.5) | 0.16% | — | Wpchill Final Tiles Grid Gallery LiteAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Stored XSS.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.13. | |
| Deferred | High (7.6) | 0.28% | — | GroundhoggAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Groundhogg groundhogg allows Blind SQL Injection.This issue affects Groundhogg: from n/a through 4.8.3. | |
| Deferred | High (7.1) | 0.10% | — | Blubrry PowerpressAI | 10/5/2026 | 10/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9. | |
| Deferred | Medium (6.5) | 0.16% | — | Stellarwp GivewpAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from n/a through 4.17.0. | |
| Deferred | Medium (4.3) | 0.21% | — | MemberfulAI | 10/5/2026 | 10/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects Memberful - Membership Plugin: from n/a through 1.81.2. | |
| Deferred | Medium (6.5) | 0.16% | — | Bplugins B BlocksAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8. |