Vulnerabilities
Summary — last 7 days
New vulnerabilities2,743▼ 119 vs. last week
Critical / high1,267▼ 261 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 186 vs. last week
59 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.1) | 58% | 💥 Exploit | Jenkins Build-metrics | 10/23/2019 | 6/17/2026 | A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin. | |
| Modified | High (7.8) | 1.4% | 💥 Exploit | Synametrics Synaman | 9/14/2018 | 6/17/2026 | Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials. | |
| Modified | Medium (4.8) | 1.7% | 💥 Exploit | Synametrics Synaman | 9/14/2018 | 6/17/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Partial Branding configuration page. | |
| Modified | Medium (6.8) | 2.0% | 💥 Exploit | Synametrics Xeams | 5/20/2015 | 6/17/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies Xeams 4.5 Build 5755 and earlier allow remote attackers to hijack the authentication of administrators for requests that create an (1) SMTP domain or a (2) user via a request to /FrontController; or conduct cross-site scripting… | |
| Modified | Low (3.7) | 74% | — | Oracle Communications Application Session ControllerOracle Communications Policy ManagementOracle Http ServerOracle Integrated Lights OUT Manager Firmware+57 | 4/1/2015 | 6/17/2026 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally… | |
| Modified | Medium (4.3) | 1.8% | 💥 Exploit | Synametrics Xeams | 6/19/2014 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote attackers to inject arbitrary web script or HTML via the body of an email. | |
| Modified | Medium (4.3) | 1.3% | — | Yandex.metrics Project Yandex Metrics | 3/27/2013 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the Yandex.Metrica service data. | |
| Modified | High (7.5) | 3.7% | 💥 Exploit | Zonemetrics Zonex Publishers Gold Edition | 8/9/2006 | 6/16/2026 | PHP remote file inclusion vulnerability in includes/usercp_register.php in ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modified | Medium (4.6) | 0.34% | — | Brian Renaud Metrics | 4/15/2004 | 6/16/2026 | The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files. |