Vulnerabilities
Summary — last 7 days
New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
39,709 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.3) | — | — | Yii2 Starter KIT Yii2-starter-kitAI | 9/30/2026 | 9/30/2026 | yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii… | |
| Awaiting Analysis | Critical (9.2) | — | — | DenoAI | 9/30/2026 | 9/30/2026 | Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process… | |
| Deferred | Critical (9.8) | — | — | Kylephillips Nested PagesAI | 9/30/2026 | 9/30/2026 | Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. | |
| Deferred | Critical (9.1) | — | — | Ptzoptics Move 4K 12XAIPtzoptics Move 4K 20XAIPtzoptics Move 4K 30XAIPtzoptics Link 4K 12XAI+35 | 9/30/2026 | 9/30/2026 | Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device… | |
| Deferred | Critical (9.1) | — | — | Quenary TugtainerAI | 9/30/2026 | 9/30/2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a… | |
| Deferred | Critical (9.8) | — | — | Quenary TugtainerAI | 9/30/2026 | 9/30/2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature… | |
| Deferred | Critical (9.4) | — | — | Quenary TugtainerAI | 9/30/2026 | 9/30/2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts… | |
| Deferred | Critical (9) | — | — | Soft MachineAI | 9/30/2026 | 9/30/2026 | Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the… | |
| Awaiting Analysis | Critical (9.2) | — | — | PythonAI | 9/30/2026 | 10/1/2026 | A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create… | |
| Deferred | Critical (9.4) | — | — | ZammadAI | 9/30/2026 | 9/30/2026 | All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. | |
| Deferred | Critical (9.4) | — | — | ZammadAI | 9/30/2026 | 9/30/2026 | Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions. | |
| Awaiting Analysis | Critical (9.3) | — | — | Internet2 GrouperAI | 9/30/2026 | 9/30/2026 | In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges. | |
| Awaiting Analysis | Critical (10) | — | — | Ordasoft Joomla CCKAI | 9/30/2026 | 9/30/2026 | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s… | |
| Awaiting Analysis | Critical (10) | — | — | Joomcode JctablesAI | 9/30/2026 | 9/30/2026 | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated… | |
| Deferred | Critical (9.8) | — | — | Trex Digital Smart Manufacturing Systems Trex MESAI | 9/30/2026 | 9/30/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29. | |
| Deferred | Critical (9.3) | — | — | LightllmAI | 9/30/2026 | 9/30/2026 | LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service… | |
| Awaiting Analysis | Critical (9.4) | — | — | Litespeed WEB ServerAI | 9/30/2026 | 9/30/2026 | LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case." | |
| Deferred | Critical (9.8) | — | — | Dolusoft Software Technologies SoplogAI | 9/30/2026 | 9/30/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1. | |
| Deferred | Critical (9.8) | — | — | Oauth Single Sign ON SSOAI | 9/30/2026 | 9/30/2026 | Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. | |
| Deferred | Critical (9.8) | — | — | Booking ActivitiesAI | 9/30/2026 | 9/30/2026 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. | |
| Deferred | Critical (9.3) | — | — | Books GalleryAI | 9/30/2026 | 9/30/2026 | Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions. | |
| Deferred | Critical (9.8) | — | — | EstatikAI | 9/30/2026 | 9/30/2026 | Subscriber Privilege Escalation in Estatik <= 4.3.5 versions. | |
| Deferred | Critical (10) | — | — | SiteskiteAI | 9/30/2026 | 9/30/2026 | Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions. | |
| Deferred | Critical (9) | — | — | Acymailing Smtp NewsletterAI | 9/30/2026 | 9/30/2026 | Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions. | |
| Awaiting Analysis | Critical (9.1) | — | — | Apache Wss4jAI | 9/30/2026 | 9/30/2026 | WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue. |