Vulnerabilities
Summary — last 7 days
New vulnerabilities2,761▲ 61 vs. last week
Critical / high1,285▼ 211 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
2,505 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | High (8.8) | 0.63% | — | Jenkins Script Security | 9/16/2026 | 9/21/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection… | |
| Analyzed | High (8.8) | 0.63% | — | Jenkins Script Security | 9/16/2026 | 9/21/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an interface method, allowing attackers with permission to define and run sandboxed… | |
| Deferred | Medium (4.3) | 0.17% | — | Subscriptions FOR WoocommerceAI | 9/16/2026 | 9/17/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make a logged-in customer cancel their own active subscription through a crafted request they are tricked into making. | |
| Deferred | Medium (5.3) | 0.34% | — | Subscriptions FOR WoocommerceAI | 9/16/2026 | 9/17/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to retrieve the store's full list of subscriptions, including customer usernames, product names, recurring amounts and payment dates. | |
| Awaiting Analysis | Critical (9.3) | 0.78% | — | GhostscriptAI | 9/15/2026 | 9/24/2026 | Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image components declare… | |
| Deferred | Critical (9.2) | 0.34% | — | Eclipse Ditto Javascript Client NodeAIEclipse Ditto Javascript Client Node 1AI | 9/8/2026 | 9/9/2026 | In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the… | |
| Analyzed | High (8.3) | 0.32% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 9/8/2026 | 9/16/2026 | Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. | |
| Analyzed | Medium (6.1) | 0.41% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 9/8/2026 | 9/16/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |
| Analyzed | Medium (6.5) | 1.1% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 9/8/2026 | 9/16/2026 | Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | |
| Analyzed | High (7.5) | 1.2% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 9/8/2026 | 9/16/2026 | Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network. | |
| Analyzed | Medium (6.5) | 0.92% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 9/8/2026 | 9/16/2026 | Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. | |
| Analyzed | High (7.1) | 0.53% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 9/8/2026 | 9/16/2026 | Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. | |
| Analyzed | High (7.5) | 0.97% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 9/8/2026 | 9/16/2026 | Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. | |
| Analyzed | Medium (6.5) | 1.1% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 9/8/2026 | 9/16/2026 | Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | |
| Analyzed | Critical (9.8) | 0.97% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 9/8/2026 | 9/16/2026 | External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. | |
| Analyzed | Medium (6.1) | 0.55% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 9/8/2026 | 9/16/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |
| Analyzed | Critical (9.1) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/22/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analyzed | Medium (5.9) | 0.47% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/29/2026 | Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | |
| Analyzed | High (8.1) | 0.69% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/29/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analyzed | High (7.5) | 1.2% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/29/2026 | Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network. | |
| Analyzed | Medium (6.5) | 0.64% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/29/2026 | Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | |
| Analyzed | Medium (6.5) | 0.84% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/29/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Analyzed | Critical (9.3) | 0.76% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/30/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analyzed | High (8.8) | 0.91% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/30/2026 | External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Analyzed | High (8.1) | 0.71% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 10/5/2026 | Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. |