Vulnerabilities
Summary — last 7 days
New vulnerabilities2,739▼ 501 vs. last week
Critical / high1,301▼ 201 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 277 vs. last week
608 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | High (7.8) | 0.14% | — | Dell Command Update | 8/19/2026 | 8/21/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analyzed | High (7.3) | 0.14% | — | Dell Command Update | 8/19/2026 | 8/21/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analyzed | High (7.3) | 0.12% | — | Dell Command Update | 8/19/2026 | 8/21/2026 | Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analyzed | Medium (6.6) | 0.17% | — | Dell Command Update | 8/19/2026 | 8/21/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analyzed | High (7.8) | 0.12% | — | Dell Command Update | 8/19/2026 | 8/21/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analyzed | High (7.8) | 0.31% | — | Dell Command Update | 8/19/2026 | 8/21/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analyzed | High (7.8) | 0.31% | — | Dell Command Update | 8/19/2026 | 8/21/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Deferred | Critical (9.8) | 0.34% | 💥 PoC | Epson Easymp Network UpdaterAI | 8/18/2026 | 9/9/2026 | Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB. | |
| Analyzed | High (7.1) | 0.24% | — | Redhat Openshift Update ServiceRedhat Quay | 8/14/2026 | 8/20/2026 | A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an… | |
| Analyzed | High (7.5) | 0.42% | — | Redhat Openshift Update ServiceRedhat Quay | 8/14/2026 | 8/20/2026 | A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This vulnerability leads to information disclosure,… | |
| Analyzed | High (7.5) | 0.23% | — | Redhat Openshift Update ServiceRedhat Quay | 8/14/2026 | 8/20/2026 | A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful exploitation can lead to the unauthorized… | |
| Analyzed | High (8.2) | 0.46% | — | Redhat Openshift Update ServiceRedhat Quay | 8/14/2026 | 8/20/2026 | A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path traversal characters into Clair API URL paths.… | |
| Analyzed | Medium (4.4) | 0.33% | — | Redhat Openshift Update ServiceRedhat Quay | 8/14/2026 | 8/20/2026 | A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses. This vulnerability also allows them to… | |
| Analyzed | Medium (6.5) | 0.31% | — | Redhat Openshift Update ServiceRedhat Quay | 8/14/2026 | 8/20/2026 | A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter metacharacters, enabling user-existence oracle… | |
| Analyzed | Medium (5.4) | 0.29% | — | Redhat Openshift Update ServiceRedhat Quay | 8/14/2026 | 8/20/2026 | A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-signed token from… | |
| Awaiting Analysis | High (7.3) | 0.18% | — | Lenovo System UpdateAI | 8/13/2026 | 8/24/2026 | A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Deferred | Critical (9.8) | 0.86% | — | Wpmudev UpdatesAI | 8/12/2026 | 8/26/2026 | The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote… | |
| Awaiting Analysis | Low (3.7) | 0.40% | — | Zephyr UpdatehubAI | 8/10/2026 | 8/26/2026 | The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS socket descriptor on its connection-setup failure paths. The shared error: cleanup gated socket closing on a ret > 0 flag, but ret was set to -1 immediately after the socket was created, so when… | |
| Awaiting Analysis | High (7.5) | 0.47% | — | Zephyr UpdatehubAI | 8/10/2026 | 8/26/2026 | The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned by the update server into a fixed two-level nested-array struct. After parsing it validates only the outer array length (objects_len != 2) and then dereferences… | |
| Awaiting Analysis | Low (3.7) | 0.35% | — | Zephyr UpdatehubAI | 8/10/2026 | 8/26/2026 | The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z_impl_updatehub_probe(). The probe response from the UpdateHub server is copied into a heap buffer (metadata) that is correctly NUL-terminated, but a second buffer (metadata_copy) is allocated with… | |
| Deferred | Medium (5.3) | 0.37% | — | Npm-check-updatesAI | 8/10/2026 | 9/24/2026 | npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability that allows an attacker to embed arbitrary terminal control characters in a dependency's package.json homepage or repository URL fields. When a developer runs ncu with the --format homepage or… | |
| Deferred | Low (2) | 0.48% | — | DiscourseAIDiscourse-local-datesAI | 8/10/2026 | 9/8/2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-local-dates plugin rendered crafted local-date format data as HTML on sites with a modified or disabled default Content Security Policy. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and… | |
| Deferred | High (7.2) | 0.46% | — | Order Delivery DateAI | 8/6/2026 | 8/12/2026 | Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. | |
| Deferred | High (7.1) | 0.16% | — | Razer RzupdateserviceAI | 8/3/2026 | 8/12/2026 | A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to… | |
| Deferred | High (8.8) | 0.21% | — | Prestashop TotadministrativemandateAI | 7/31/2026 | 8/31/2026 | PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link. |