Vulnerabilities

Summary — last 7 days

New vulnerabilities2,758▼ 17 vs. last week
Critical / high1,269▼ 209 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 185 vs. last week
–

59 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (4.3)0.28%—Loway Queuemetrics9/8/20246/17/2026
Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
AnalyzedMedium (6.1)0.24%—Loway Queuemetrics9/8/20246/17/2026
Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
ModifiedCritical (9.8)0.79%—Camsbiometrics Zkteco, Essl, Cams Biometrics Integration ModuleOdoo Biometric Attendance12/15/20236/17/2026
SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component.
ModifiedMedium (4.8)0.37%—Riyaz Social Metrics10/2/20236/17/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Riyaz Social Metrics plugin <= 2.2 versions.
ModifiedMedium (5.4)0.39%—Monsterinsights Exactmetrics8/8/20236/17/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExactMetrics plugin <= 7.14.1 versions.
ModifiedHigh (8.2)0.57%—Jenkins Visual Studio Code Metrics4/2/20236/17/2026
Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModifiedMedium (6.1)0.53%—Baremetrics Date Range Picker2/21/20236/17/2026
The Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender view. Versions 1.0.14 and prior are prone to cross-site scripting (XSS) when handling untrusted `placeholder` entries. An attacker who is able to influence the field `placeholder` when creating a…
ModifiedMedium (5.4)0.57%—Exactmetrics2/6/20236/17/2026
The ExactMetrics WordPress plugin before 7.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModifiedCritical (9.8)0.60%—Kbase Metrics12/30/20226/17/2026
A vulnerability was found in KBase Metrics. It has been classified as critical. This affects the function upload_user_data of the file source/daily_cron_jobs/methods_upload_user_stats.py. The manipulation leads to sql injection. The patch is named 959dfb6b05991e30b0fa972a1ecdcaae8e1dae6d. It is recommended to apply a…
ModifiedHigh (8.8)0.49%—Grafana Enterprise Metrics12/20/20226/17/2026
A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector restrictions will not be applied when using…
ModifiedMedium (4.3)0.68%—Jenkins Build-metrics6/30/20226/17/2026
Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.
ModifiedMedium (5.4)0.75%—Jenkins Build-metrics6/30/20226/17/2026
Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Build/Update permission.
ModifiedHigh (7.2)1.9%—Synametrics Synaman4/6/20227/9/2026
The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.
ModifiedHigh (7.8)0.31%—Synametrics Synaman4/6/20227/9/2026
Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges.
ModifiedHigh (7.5)2.1%💥 PoCSynametrics Synaman1/27/20226/17/2026
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
ModifiedMedium (5.5)0.32%—Jenkins Metrics1/12/20226/17/2026
Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
ModifiedHigh (8.1)0.74%—Metrics-util Project Metrics-util12/27/20216/17/2026
An issue was discovered in the metrics-util crate before 0.7.0 for Rust. There is a data race and memory corruption because AtomicBucket<T> unconditionally implements the Send and Sync traits.
ModifiedMedium (5.5)0.28%—Grafana Enterprise Metrics4/30/20216/17/2026
The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can…
ModifiedMedium (6.5)0.92%—Cloud Foundry Bosh System Metrics Server10/2/20206/17/2026
BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).
ModifiedHigh (8.8)1.4%—Loway Queuemetrics9/9/20206/17/2026
A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.04.1 allows remote authenticated attackers to execute arbitrary SQL commands via the TASKS_LIST__pt.querystring parameter.
ModifiedHigh (8.8)1.1%—Loway Queuemetrics8/13/20206/17/2026
A SQL injection vulnerability in the qm_adm/qm_export_stats_run.do endpoint of Loway QueueMetrics before 19.10.21 allows remote authenticated users to execute arbitrary SQL commands via the exportId parameter.
ModifiedHigh (8.8)1.1%—Loway Queuemetrics8/13/20206/17/2026
A SQL injection vulnerability at a tpf URI in Loway QueueMetrics before 19.10.21 allows remote authenticated attackers to execute arbitrary SQL commands via the TPF_XPAR1 parameter.
ModifiedCritical (9.8)1.3%—Nanometrics CentaurNanometrics Titansma4/24/20206/17/2026
Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
ModifiedHigh (8.8)1.3%💥 ExploitSynametrics SynamanSynametrics SyncrifySynametrics Syntail11/21/20196/17/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567
ModifiedMedium (6.5)1.8%—Kubernetes Kube-state-metricsRedhat Openshift Container Platform11/5/20196/17/2026
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl`…