Vulnerabilities
Summary — last 7 days
New vulnerabilities2,558▼ 318 vs. last week
Critical / high1,344▲ 80 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
401,075 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.7) | 0.31% | — | GhostAI | 10/2/2026 | 10/2/2026 | Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff invites. Staff users with invite viewing permission can accept pending invites for higher-privileged roles to escalate their privileges. | |
| Deferred | Low (2.3) | 0.21% | — | GhostAI | 10/2/2026 | 10/2/2026 | Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other staff users' password hashes. Authenticated staff users can query the Admin API to infer hash ordering, though this does not directly reveal hashes… | |
| Deferred | High (8.6) | 0.28% | — | GhostAI | 10/2/2026 | 10/2/2026 | Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. Attackers can host malicious oEmbed photo responses so that embedding their URL stores scripts that run in the Ghost editor, published… | |
| Deferred | High (8.5) | 0.26% | — | GhostAI | 10/2/2026 | 10/2/2026 | Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card image fetching. Attackers can create bookmark cards that store non-image files from external websites as icons or thumbnails to… | |
| Deferred | Medium (5.3) | 0.19% | — | GhostAI | 10/2/2026 | 10/2/2026 | Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role to other staff despite lacking permission to do so. An authenticated Editor or Super Editor can promote Author and Contributor users to Editor or Super Editor. | |
| Deferred | High (8.5) | 0.26% | — | GhostAI | 10/2/2026 | 10/2/2026 | Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content types on the default local storage adapter. Attackers can upload script-bearing files to the site's domain to compromise other staff… | |
| Deferred | High (8.7) | 0.38% | — | B3log SiyuanAI | 10/2/2026 | 10/2/2026 | SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows'… | |
| Deferred | Medium (6.9) | 0.31% | — | B3log SiyuanAI | 10/2/2026 | 10/2/2026 | SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded documents through the getNotebookInfo endpoint. Attackers, including anonymous visitors when no reader password is set, can query publish-visible notebooks to obtain… | |
| Deferred | Medium (6.9) | 0.24% | — | B3log SiyuanAI | 10/2/2026 | 10/2/2026 | SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to… | |
| Awaiting Analysis | Medium (6.4) | 0.11% | — | GNU GrubAI | 10/2/2026 | 10/2/2026 | A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled. The vulnerability is caused by insufficient validation of the MMIO base address passed to the GRUB serial command.… | |
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.2) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.7) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Uncaught exception vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.7) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.7) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Missing release of memory after effective lifetime, Missing release of resource after effective lifetime vulnerability in Apache Thrift THeaderTransport. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.7) | 0.46% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Stack-based buffer overflow, Incorrect bitwise shift of integer vulnerability in Apache Thrift C++ THeaderProtocol. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | High (8.7) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Improper validation of specified quantity in input, Allocation of resources without limits or throttling, Excessive Iteration vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. | |
| Deferred | Critical (9.2) | 0.46% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does not compress, such as content a remote peer… | |
| Awaiting Analysis | High (8.6) | 0.19% | — | — | 10/2/2026 | 10/2/2026 | An improper verification of cryptographic signature vulnerability exists in protocol gateways because the device does not properly verify the cryptographic authenticity of firmware images before installation. An attacker with high privileges and access to the firmware update interface could provide a specially crafted… | |
| Awaiting Analysis | Critical (9.4) | 0.34% | — | — | 10/2/2026 | 10/2/2026 | A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a read-only user to the web management interface… | |
| Deferred | High (8.7) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings. This… | |
| Deferred | High (8.7) | 0.43% | — | Apache ThriftAI | 10/2/2026 | 10/2/2026 | Uncontrolled Recursion vulnerability in Apache Thrift Dart and Java ME bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. |