Vulnerabilities
Summary — last 7 days
New vulnerabilities3,008▲ 385 vs. last week
Critical / high1,453▲ 24 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
4,643 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Critical (9.3) | 0.27% | — | Servicenow AI PlatformAI | 9/24/2026 | 9/24/2026 | ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data… | |
| Deferred | Medium (6.5) | 0.21% | — | Global IT Informatics Technology Services INC WeollAI | 9/23/2026 | 9/23/2026 | Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery. This issue affects Weoll: before 3.2.45.44. | |
| Awaiting Analysis | High (8.6) | 1.7% | — | Zohocorp Manageengine Adselfservice PlusAI | 9/22/2026 | 9/22/2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API. | |
| Awaiting Analysis | Critical (9.8) | 4.6% | — | Zohocorp Manageengine Adselfservice PlusAI | 9/22/2026 | 9/23/2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. | |
| Awaiting Analysis | Medium (6.1) | 0.20% | — | IBM Financial Transaction Manager FOR Swift Services FOR MultiplatformsAI | 9/18/2026 | 9/22/2026 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Undergoing Analysis | Low (3.1) | 0.15% | — | HCL Bigfix Service ManagementAI | 9/18/2026 | 9/18/2026 | HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized attacker to predict or hijack valid session identifiers. Successful exploitation… | |
| Undergoing Analysis | Low (3.1) | 0.25% | — | HCL Bigfix Service ManagementAI | 9/18/2026 | 9/18/2026 | HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets. | |
| Undergoing Analysis | Low (3.1) | 0.24% | — | HCL Bigfix Service ManagementAI | 9/18/2026 | 9/18/2026 | HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of… | |
| Undergoing Analysis | Medium (6.5) | 0.45% | — | HCL Bigfix Service ManagementAI | 9/18/2026 | 9/18/2026 | HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute sustained brute-force attacks against the login interface, resulting in unauthorized system access. | |
| Undergoing Analysis | Medium (6.4) | 0.29% | — | HCL Bigfix Service ManagementAI | 9/18/2026 | 9/18/2026 | HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a complete server compromise. | |
| Undergoing Analysis | Medium (5) | 0.16% | — | HCL Bigfix Service ManagementAI | 9/18/2026 | 9/18/2026 | HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries. | |
| Analyzed | Medium (6.1) | 0.20% | — | Hcltech Bigfix Service Management | 9/18/2026 | 10/8/2026 | HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of affected users. | |
| Analyzed | High (8.1) | 0.35% | — | Hcltech Bigfix Service Management | 9/18/2026 | 10/8/2026 | HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles. | |
| Analyzed | Medium (5.8) | 0.26% | — | Hcltech Bigfix Service Management | 9/18/2026 | 10/8/2026 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet. | |
| Analyzed | Critical (9.8) | 0.47% | — | Hcltech Bigfix Service Management | 9/18/2026 | 10/8/2026 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile… | |
| Analyzed | Critical (10) | 14% | ⚠ Active exploitation💥 PoC | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 9/16/2026 | 10/7/2026 | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API… | |
| Analyzed | Medium (4.9) | 0.43% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 9/16/2026 | 9/28/2026 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs… | |
| Analyzed | Medium (4.9) | 0.43% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 9/16/2026 | 9/28/2026 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs… | |
| Analyzed | Medium (4.9) | 0.43% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 9/16/2026 | 9/28/2026 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs… | |
| Analyzed | Medium (4.9) | 0.43% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 9/16/2026 | 9/28/2026 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs… | |
| Analyzed | Medium (5.3) | 0.38% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 9/16/2026 | 9/28/2026 | A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing authentication on a function of the OCSP… | |
| Analyzed | Medium (4.9) | 0.30% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 9/16/2026 | 9/28/2026 | A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific files on the underlying operating system of an affected device. This vulnerability is due to improper restriction of XML external entity references. An attacker could exploit this vulnerability… | |
| Analyzed | Medium (5.3) | 0.29% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 9/16/2026 | 9/28/2026 | A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could… | |
| Analyzed | Medium (5.3) | 0.32% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 9/16/2026 | 9/28/2026 | A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to submit forged posture status events into the endpoint posture pipeline. This vulnerability is due to insufficient authentication on an internal… | |
| Analyzed | Medium (4.9) | 0.38% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 9/16/2026 | 9/28/2026 | A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This… |