Vulnerabilities

Summary — last 7 days

New vulnerabilities2,761▲ 61 vs. last week
Critical / high1,285▼ 211 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
–

2,505 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedHigh (8.8)0.63%—Jenkins Script Security9/16/20269/21/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection…
AnalyzedHigh (8.8)0.63%—Jenkins Script Security9/16/20269/21/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowing attackers with permission to define and run sandboxed…
DeferredMedium (4.3)0.17%—Subscriptions FOR WoocommerceAI9/16/20269/17/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making.
DeferredMedium (5.3)0.34%—Subscriptions FOR WoocommerceAI9/16/20269/17/2026
The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, including customer usernames, product names, recurring amounts and payment dates.
Awaiting AnalysisCritical (9.3)0.78%—GhostscriptAI9/15/20269/24/2026
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare…
DeferredCritical (9.2)0.34%—Eclipse Ditto Javascript Client NodeAIEclipse Ditto Javascript Client Node 1AI9/8/20269/9/2026
In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the…
AnalyzedHigh (8.3)0.32%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition9/8/20269/16/2026
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
AnalyzedMedium (6.1)0.41%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition9/8/20269/16/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
AnalyzedMedium (6.5)1.1%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition9/8/20269/16/2026
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
AnalyzedHigh (7.5)1.2%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition9/8/20269/16/2026
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
AnalyzedMedium (6.5)0.92%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition9/8/20269/16/2026
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
AnalyzedHigh (7.1)0.53%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition9/8/20269/16/2026
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
AnalyzedHigh (7.5)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition9/8/20269/16/2026
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
AnalyzedMedium (6.5)1.1%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition9/8/20269/16/2026
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
AnalyzedCritical (9.8)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition9/8/20269/16/2026
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
AnalyzedMedium (6.1)0.55%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition9/8/20269/16/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
AnalyzedCritical (9.1)0.86%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/8/20269/22/2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalyzedMedium (5.9)0.47%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/8/20269/29/2026
Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
AnalyzedHigh (8.1)0.69%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/8/20269/29/2026
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalyzedHigh (7.5)1.2%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/8/20269/29/2026
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
AnalyzedMedium (6.5)0.64%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/8/20269/29/2026
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
AnalyzedMedium (6.5)0.84%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/8/20269/29/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
AnalyzedCritical (9.3)0.76%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/8/20269/30/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalyzedHigh (8.8)0.91%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/8/20269/30/2026
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
AnalyzedHigh (8.1)0.71%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/8/202610/5/2026
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.