Vulnerabilities
Summary — last 7 days
New vulnerabilities3,332▲ 359 vs. last week
Critical / high1,490▲ 132 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
400,204 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (2.1) | — | — | Itsourcecode Leave Management SystemAI | 10/1/2026 | 10/1/2026 | A vulnerability has been found in itsourcecode Leave Management System 1.0. The affected element is an unknown function of the file /module/leavetype/controller.php. Such manipulation of the argument LEAVTID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Deferred | Low (2.1) | — | — | Formtools Form ToolsAI | 10/1/2026 | 10/1/2026 | A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX Endpoint. This manipulation of the argument url causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may… | |
| Deferred | Low (2.1) | — | — | Formtools Form ToolsAI | 10/1/2026 | 10/1/2026 | A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the function Files::uploadFile of the file global/code/actions.php of the component Ajax Handler. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit is now public and may be… | |
| Deferred | Low (2.1) | — | — | Formtools Form ToolsAI | 10/1/2026 | 10/1/2026 | A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation of the argument page_titles leads to improper neutralization of… | |
| Received | Critical (10) | — | — | Backupsheep Wordpress Backup PluginAI | 10/1/2026 | 10/1/2026 | The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files… | |
| Received | High (8.8) | — | — | Fifu Featured Image From URLAI | 10/1/2026 | 10/1/2026 | The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which could allow attackers to make a logged-in administrator perform… | |
| Deferred | Critical (9.1) | — | — | LatepointAI | 10/1/2026 | 10/1/2026 | The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running… | |
| Deferred | Medium (5.3) | — | — | WP Popular PostsAI | 10/1/2026 | 10/1/2026 | The WP Popular Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2 via the 'context' parameter. This makes it possible for unauthenticated attackers to extract sensitive edit-context fields — including raw title, raw content body, password, meta,… | |
| Deferred | Critical (9.3) | — | — | Hitachi Coding Software SuiteAI | 10/1/2026 | 10/1/2026 | Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Deferred | High (8.7) | — | — | Hitachi Coding Software SuiteAI | 10/1/2026 | 10/1/2026 | Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Deferred | Critical (9.3) | — | — | Hitachi Coding Software SuiteAI | 10/1/2026 | 10/1/2026 | Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Deferred | High (8.7) | — | — | Hitachi Coding Software SuiteAI | 10/1/2026 | 10/1/2026 | Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Deferred | Critical (9.3) | — | — | Hitachi Coding Software SuiteAI | 10/1/2026 | 10/1/2026 | Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation. This issue affects… | |
| Deferred | Critical (9.3) | — | — | Hitachi Coding Software SuiteAI | 10/1/2026 | 10/1/2026 | Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0. | |
| Awaiting Analysis | High (7.1) | — | — | Octopus ServerAI | 10/1/2026 | 10/1/2026 | In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts in an environment without possessing the required authorization. | |
| Deferred | Medium (5.9) | — | — | Genian NAC ZtnaAI | 10/1/2026 | 10/1/2026 | A path traversal (ZIP Slip) vulnerability caused by insufficient authorization and integrity verification in the agent upgrade feature of Genian NAC/ZTNA allows a remote attacker to execute arbitrary code | |
| Deferred | High (8.4) | — | — | Genian SSL PNSAI | 10/1/2026 | 10/1/2026 | An OS command injection vulnerability in Genian SSL PNS allows an attacker who knows only the client access ID, without the password, to execute arbitrary commands remotely | |
| Deferred | High (7.5) | — | — | Genian SSL PNSAI | 10/1/2026 | 10/1/2026 | An improper privilege management vulnerability in Genian SSL PNS allows an attacker to escalate to super administrator privileges and force the creation of an OS account by manipulating the permission column during CSV bulk user registration | |
| Deferred | Low (1.8) | — | — | Genian SSL PNSAI | 10/1/2026 | 10/1/2026 | An unrestricted file upload vulnerability caused by insufficient file extension and integrity verification in Genian SSL PNS allows an attacker to upload a dangerous file that is not an official patch | |
| Deferred | High (7.3) | — | — | Genian SSL PNSAI | 10/1/2026 | 10/1/2026 | A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter. | |
| Deferred | Critical (9.3) | — | — | Genian NAC Ztna Policy ServerAI | 10/1/2026 | 10/1/2026 | Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions | |
| Deferred | Medium (5.4) | — | — | Advanced-woo-labels Advanced WOO LabelsAI | 10/1/2026 | 10/1/2026 | The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improperly secure capability check on the 'save_meta_boxes' function in all versions up to, and including, 2.51. This makes it possible for authenticated attackers, with… | |
| Deferred | Low (2.1) | — | — | Zongxr SupermarketAI | 10/1/2026 | 10/1/2026 | A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The… | |
| Deferred | Medium (5.5) | — | — | Zongxr SupermarketAI | 10/1/2026 | 10/1/2026 | A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results… | |
| Deferred | Medium (5.5) | — | — | Zongxr SupermarketAI | 10/1/2026 | 10/1/2026 | A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing… |