Vulnerabilities

Summary — last 7 days

New vulnerabilities2,761▲ 5 vs. last week
Critical / high1,274▼ 254 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)245▲ 227 vs. last week
–

1,756 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedCritical (9.3)0.64%—Adobe ConnectAdobe Connect FOR Mobile9/22/20269/25/2026
Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a…
AnalyzedCritical (9.3)0.30%—Adobe ConnectAdobe Connect FOR Mobile9/22/20269/26/2026
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining…
AnalyzedCritical (9.9)0.55%—Adobe ConnectAdobe Connect FOR Mobile9/22/20269/25/2026
Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially…
AnalyzedMedium (6.1)0.18%—Adobe ConnectAdobe Connect FOR Mobile9/22/20269/25/2026
Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
AnalyzedHigh (8.6)0.66%—Adobe ConnectAdobe Connect FOR Mobile9/22/20269/25/2026
Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this…
Awaiting AnalysisHigh (7.1)0.30%—Canva Mobile APPAI9/21/20269/21/2026
The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
AnalyzedHigh (7.4)0.10%—Qualcomm Cologne FirmwareQualcomm Congo FirmwareQualcomm Cq7790 FirmwareQualcomm Cq7790m Firmware+719/17/20269/22/2026
Transient DOS while parsing frame during channel usage.
AnalyzedHigh (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+3729/17/20269/22/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
AnalyzedHigh (7.4)0.10%—Qualcomm Ar8035 FirmwareQualcomm C110100 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+1489/17/20269/22/2026
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
Awaiting AnalysisCritical (9.3)1.6%—WNC T-mobile 5G BOX IDUAI9/16/20269/28/2026
WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an authenticated attacker to execute arbitrary…
Awaiting AnalysisCritical (9.4)2.9%—WNC T-mobile 5G BOX IDUAI9/16/20269/28/2026
WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is directly concatenated into a find command string without proper sanitization. This…
Awaiting AnalysisHigh (8.4)0.20%—WNC T-mobile 5G BOX IDUAI9/16/20269/28/2026
WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by…
Awaiting AnalysisHigh (7.1)0.37%—WNC T-mobile 5G BOX IDUAI9/16/20269/28/2026
WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web password, WiFi passphrase, and technical…
Awaiting AnalysisCritical (9.3)1.6%—WNC T-mobile 5G BOX IDUAI9/16/20269/28/2026
WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify and sanitize user-supplied input before…
Awaiting AnalysisHigh (8.7)0.32%—WNC T-mobile 5G BOX IDU RouterAI9/16/20269/28/2026
WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory…
AnalyzedHigh (8.2)0.31%—Oracle Mobile Application Server9/15/202610/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Application…
AnalyzedHigh (8.1)0.37%—Oracle Mobile Application Server9/15/202610/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
AnalyzedHigh (7.5)0.24%—Oracle Mobile Application Server9/15/202610/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the…
AnalyzedCritical (9.8)0.48%—Oracle Mobile Application Server9/15/202610/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
AnalyzedHigh (8.2)0.42%—Oracle Mobile Application Server9/15/202610/9/2026
Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application…
AnalyzedHigh (8.8)0.35%—Mozilla Firefox Mobile9/15/202610/5/2026
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
DeferredHigh (7.5)0.40%—Mdjm Event ManagementAIMobileeventsmanager Mobile Events ManagerAI9/13/20269/14/2026
The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to…
AnalyzedMedium (5)0.19%—Adobe Photoshop Mobile9/8/20269/9/2026
Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions.…
AnalyzedHigh (7.4)0.21%—Adobe Photoshop Mobile9/8/20269/9/2026
Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a…
AnalyzedHigh (8.8)1.0%—Ivanti Endpoint Manager Mobile9/8/20269/9/2026
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.