Vulnerabilities
Summary — last 7 days
New vulnerabilities2,758▼ 17 vs. last week
Critical / high1,269▼ 209 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 185 vs. last week
59 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (4.3) | 0.28% | — | Loway Queuemetrics | 9/8/2024 | 6/17/2026 | Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | |
| Analyzed | Medium (6.1) | 0.24% | — | Loway Queuemetrics | 9/8/2024 | 6/17/2026 | Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | |
| Modified | Critical (9.8) | 0.79% | — | Camsbiometrics Zkteco, Essl, Cams Biometrics Integration ModuleOdoo Biometric Attendance | 12/15/2023 | 6/17/2026 | SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component. | |
| Modified | Medium (4.8) | 0.37% | — | Riyaz Social Metrics | 10/2/2023 | 6/17/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Riyaz Social Metrics plugin <= 2.2 versions. | |
| Modified | Medium (5.4) | 0.39% | — | Monsterinsights Exactmetrics | 8/8/2023 | 6/17/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExactMetrics plugin <= 7.14.1 versions. | |
| Modified | High (8.2) | 0.57% | — | Jenkins Visual Studio Code Metrics | 4/2/2023 | 6/17/2026 | Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modified | Medium (6.1) | 0.53% | — | Baremetrics Date Range Picker | 2/21/2023 | 6/17/2026 | The Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender view. Versions 1.0.14 and prior are prone to cross-site scripting (XSS) when handling untrusted `placeholder` entries. An attacker who is able to influence the field `placeholder` when creating a… | |
| Modified | Medium (5.4) | 0.57% | — | Exactmetrics | 2/6/2023 | 6/17/2026 | The ExactMetrics WordPress plugin before 7.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modified | Critical (9.8) | 0.60% | — | Kbase Metrics | 12/30/2022 | 6/17/2026 | A vulnerability was found in KBase Metrics. It has been classified as critical. This affects the function upload_user_data of the file source/daily_cron_jobs/methods_upload_user_stats.py. The manipulation leads to sql injection. The patch is named 959dfb6b05991e30b0fa972a1ecdcaae8e1dae6d. It is recommended to apply a… | |
| Modified | High (8.8) | 0.49% | — | Grafana Enterprise Metrics | 12/20/2022 | 6/17/2026 | A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector restrictions will not be applied when using… | |
| Modified | Medium (4.3) | 0.68% | — | Jenkins Build-metrics | 6/30/2022 | 6/17/2026 | Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them. | |
| Modified | Medium (5.4) | 0.75% | — | Jenkins Build-metrics | 6/30/2022 | 6/17/2026 | Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Build/Update permission. | |
| Modified | High (7.2) | 1.9% | — | Synametrics Synaman | 4/6/2022 | 7/9/2026 | The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges. | |
| Modified | High (7.8) | 0.31% | — | Synametrics Synaman | 4/6/2022 | 7/9/2026 | Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges. | |
| Modified | High (7.5) | 2.1% | 💥 PoC | Synametrics Synaman | 1/27/2022 | 6/17/2026 | An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string. | |
| Modified | Medium (5.5) | 0.32% | — | Jenkins Metrics | 1/12/2022 | 6/17/2026 | Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modified | High (8.1) | 0.74% | — | Metrics-util Project Metrics-util | 12/27/2021 | 6/17/2026 | An issue was discovered in the metrics-util crate before 0.7.0 for Rust. There is a data race and memory corruption because AtomicBucket<T> unconditionally implements the Send and Sync traits. | |
| Modified | Medium (5.5) | 0.28% | — | Grafana Enterprise Metrics | 4/30/2021 | 6/17/2026 | The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can… | |
| Modified | Medium (6.5) | 0.92% | — | Cloud Foundry Bosh System Metrics Server | 10/2/2020 | 6/17/2026 | BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details). | |
| Modified | High (8.8) | 1.4% | — | Loway Queuemetrics | 9/9/2020 | 6/17/2026 | A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.04.1 allows remote authenticated attackers to execute arbitrary SQL commands via the TASKS_LIST__pt.querystring parameter. | |
| Modified | High (8.8) | 1.1% | — | Loway Queuemetrics | 8/13/2020 | 6/17/2026 | A SQL injection vulnerability in the qm_adm/qm_export_stats_run.do endpoint of Loway QueueMetrics before 19.10.21 allows remote authenticated users to execute arbitrary SQL commands via the exportId parameter. | |
| Modified | High (8.8) | 1.1% | — | Loway Queuemetrics | 8/13/2020 | 6/17/2026 | A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.10.21 allows remote authenticated attackers to execute arbitrary SQL commands via the TPF_XPAR1 parameter. | |
| Modified | Critical (9.8) | 1.3% | — | Nanometrics CentaurNanometrics Titansma | 4/24/2020 | 6/17/2026 | Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log. | |
| Modified | High (8.8) | 1.3% | 💥 Exploit | Synametrics SynamanSynametrics SyncrifySynametrics Syntail | 11/21/2019 | 6/17/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567 | |
| Modified | Medium (6.5) | 1.8% | — | Kubernetes Kube-state-metricsRedhat Openshift Container Platform | 11/5/2019 | 6/17/2026 | A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl`… |