Vulnerabilities

Summary — last 7 days

New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
–

39,709 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredCritical (9.3)——Yii2 Starter KIT Yii2-starter-kitAI9/30/20269/30/2026
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii…
Awaiting AnalysisCritical (9.2)——DenoAI9/30/20269/30/2026
Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process…
DeferredCritical (9.8)——Kylephillips Nested PagesAI9/30/20269/30/2026
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
DeferredCritical (9.1)——Ptzoptics Move 4K 12XAIPtzoptics Move 4K 20XAIPtzoptics Move 4K 30XAIPtzoptics Link 4K 12XAI+359/30/20269/30/2026
Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device…
DeferredCritical (9.1)——Quenary TugtainerAI9/30/20269/30/2026
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a…
DeferredCritical (9.8)——Quenary TugtainerAI9/30/20269/30/2026
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature…
DeferredCritical (9.4)——Quenary TugtainerAI9/30/20269/30/2026
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts…
DeferredCritical (9)——Soft MachineAI9/30/20269/30/2026
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the…
Awaiting AnalysisCritical (9.2)——PythonAI9/30/202610/1/2026
A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create…
DeferredCritical (9.4)——ZammadAI9/30/20269/30/2026
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
DeferredCritical (9.4)——ZammadAI9/30/20269/30/2026
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Awaiting AnalysisCritical (9.3)——Internet2 GrouperAI9/30/20269/30/2026
In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.
Awaiting AnalysisCritical (10)——Ordasoft Joomla CCKAI9/30/20269/30/2026
Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s…
Awaiting AnalysisCritical (10)——Joomcode JctablesAI9/30/20269/30/2026
Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated…
DeferredCritical (9.8)——Trex Digital Smart Manufacturing Systems Trex MESAI9/30/20269/30/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29.
DeferredCritical (9.3)——LightllmAI9/30/20269/30/2026
LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service…
Awaiting AnalysisCritical (9.4)——Litespeed WEB ServerAI9/30/20269/30/2026
LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."
DeferredCritical (9.8)——Dolusoft Software Technologies SoplogAI9/30/20269/30/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.
DeferredCritical (9.8)——Oauth Single Sign ON SSOAI9/30/20269/30/2026
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
DeferredCritical (9.8)——Booking ActivitiesAI9/30/20269/30/2026
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
DeferredCritical (9.3)——Books GalleryAI9/30/20269/30/2026
Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.
DeferredCritical (9.8)——EstatikAI9/30/20269/30/2026
Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.
DeferredCritical (10)——SiteskiteAI9/30/20269/30/2026
Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
DeferredCritical (9)——Acymailing Smtp NewsletterAI9/30/20269/30/2026
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Awaiting AnalysisCritical (9.1)——Apache Wss4jAI9/30/20269/30/2026
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.