Vulnerabilities

Summary — last 7 days

New vulnerabilities3,247▲ 705 vs. last week
Critical / high1,522▲ 137 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)235▲ 221 vs. last week
–

404,332 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.4)0.09%—Mitel Linux Virtual MachineAI10/5/202610/6/2026
DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object…
DeferredLow (1.9)0.25%——10/5/202610/6/2026
DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content, resulting in a denial-of-service condition within the web application. The specific flaw exists within the web portal listening on TCP port 443,…
DeferredLow (1.9)0.25%——10/5/202610/6/2026
DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application. The specific flaw exists within the web portal listening on TCP port 443, under Configuration → Domains, specifically in…
DeferredMedium (5.5)0.31%——10/5/202610/6/2026
DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory. The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate…
DeferredHigh (8.5)0.22%——10/5/202610/6/2026
DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration. The specific flaw exists within the backup restoration mechanism, which fails to properly…
DeferredHigh (8.4)0.14%——10/5/202610/6/2026
DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs
DeferredMedium (4.3)0.17%—Stellarwp Event TicketsAI10/5/202610/6/2026
Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.
DeferredMedium (6.5)0.16%—Sonaar MP3 Audio Player FOR Music Radio PodcastAI10/5/202610/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.14.2.
DeferredMedium (6.5)0.16%—Wpchill Final Tiles Grid Gallery LiteAI10/5/202610/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Stored XSS.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.13.
DeferredHigh (7.6)0.28%—GroundhoggAI10/5/202610/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Groundhogg groundhogg allows Blind SQL Injection.This issue affects Groundhogg: from n/a through 4.8.3.
DeferredHigh (7.1)0.10%—Blubrry PowerpressAI10/5/202610/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
DeferredMedium (6.5)0.16%—Stellarwp GivewpAI10/5/202610/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from n/a through 4.17.0.
DeferredMedium (4.3)0.21%—MemberfulAI10/5/202610/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects Memberful - Membership Plugin: from n/a through 1.81.2.
DeferredMedium (6.5)0.16%—Bplugins B BlocksAI10/5/202610/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8.
DeferredMedium (5.3)0.23%—Jeroen Peters Name DirectoryAI10/5/202610/6/2026
Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Name Directory: from n/a through 1.34.2.
DeferredMedium (6.5)0.16%—Jeroen Peters Name DirectoryAI10/5/202610/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Name Directory name-directory allows Stored XSS.This issue affects Name Directory: from n/a through 1.34.2.
DeferredHigh (8.5)0.26%—SirvAI10/5/202610/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sirv Sirv sirv allows Blind SQL Injection.This issue affects Sirv: from n/a through 8.2.5.
DeferredMedium (5.3)0.23%—Blubrry PowerpressAI10/5/202610/6/2026
Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
DeferredMedium (6.5)0.15%—Rextheme WP VRAI10/5/202610/6/2026
Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 9.1.3.
Awaiting AnalysisMedium (5.3)0.37%—Perforce P4 SearchAI10/5/202610/6/2026
Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain authentication requests. An attacker holding a stolen P4 Server ticket can bypass host-based ticket restrictions and trusted-address controls, gaining access to P4 Search as the ticket's owner.
Awaiting AnalysisMedium (5.1)0.33%—Perforce P4 SearchAI10/5/202610/6/2026
Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installation directory.
Awaiting AnalysisCritical (9.5)0.35%—Perforce P4 SearchAI10/5/202610/6/2026
P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affected configurations, an unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to compromise of P4 Search and the connected P4 Server.
Awaiting AnalysisHigh (7.5)0.51%—Perforce P4 SearchAI10/5/202610/6/2026
Perforce P4 Search prior to 2026.4.2 does not restrict file paths written through its logging configuration interface. An attacker holding the service authentication token can write arbitrary files on the host, potentially leading to code execution as the P4 Search service account.
DeferredMedium (5.3)0.23%—Magepeople Taxi Booking ManagerAI10/5/202610/6/2026
Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1.
DeferredMedium (5.3)0.28%—Deepen Bajracharya Video Conferencing With ZoomAI10/5/202610/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Retrieve Embedded Sensitive Data.This issue affects Video Conferencing with Zoom: from n/a through 4.6.10.