Vulnerabilities
Summary — last 7 days
New vulnerabilities2,722▼ 518 vs. last week
Critical / high1,296▼ 206 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)226▼ 276 vs. last week
610 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Critical (9.3) | 19% | ⚠ Active exploitation💥 Exploit | Sangoma Switchvox | 7/17/2026 | 9/3/2026 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated… | |
| Deferred | High (8.6) | 0.55% | — | Sangoma Switchvox SMB EditionAI | 7/17/2026 | 7/17/2026 | An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalid_browser and invalid_browser_login handlers. User-supplied data is reflected into JavaScript… | |
| Deferred | High (8.5) | 0.20% | — | Punto SwitcherAI | 6/18/2026 | 6/23/2026 | Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to execute arbitrary code by exploiting the application's call to WinExec without a fully qualified path for RunDll32.exe when invoking shell32.dll Control_RunDLL input.dll. Attackers can place a… | |
| Deferred | High (7.2) | 0.24% | — | Mitsubishielectric Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Packaged AIR ConditionersAIMitsubishielectric RefrigeratorsAI+12 | 6/17/2026 | 6/17/2026 | Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump… | |
| Deferred | High (8.7) | 1.3% | — | Managed Ethernet SwitchAI | 6/16/2026 | 6/17/2026 | Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise. | |
| Analyzed | Medium (4.3) | 0.29% | — | Freeswitch | 6/9/2026 | 7/23/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's check_auth userauth branch wrote request-supplied userVariables into the connection state before… | |
| Analyzed | High (7.5) | 0.53% | — | Freeswitch | 6/9/2026 | 7/23/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, a single unauthenticated WebSocket frame containing a deeply nested JSON document crashes the FreeSWITCH… | |
| Analyzed | Medium (5.3) | 0.50% | — | Freeswitch | 6/9/2026 | 7/23/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's JSON-RPC handler bound the connection to the client-supplied sessid on the first frame, before the… | |
| Analyzed | High (7.5) | 0.58% | — | Freeswitch | 6/9/2026 | 7/23/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's WebSocket frame loop intercepts a #-prefixed speed-test protocol (#SPU / #SPB / #SPE) before any… | |
| Analyzed | Critical (9.8) | 0.60% | — | Freeswitch | 6/9/2026 | 7/23/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB buffer for a POST application/x-www-form-urlencoded… | |
| Analyzed | Critical (9.1) | 0.48% | — | Freeswitch | 6/9/2026 | 7/23/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight to malloc(len + 1) with no… | |
| Analyzed | High (7.5) | 0.49% | — | Freeswitch | 6/9/2026 | 7/23/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, a STUN packet whose declared attribute length is shorter than the structure the parser casts to causes the… | |
| Analyzed | Medium (5.3) | 0.37% | — | Freeswitch | 6/9/2026 | 7/23/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH includes a vulnerable function, PREFIX(prologTok)(), in… | |
| Analyzed | High (7.5) | 0.49% | — | Freeswitch | 6/9/2026 | 7/20/2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH's bundled XML parser expands nested <!ENTITY> declarations without a depth or count bound, so a… | |
| Awaiting Analysis | Medium (6.5) | 0.41% | — | OpenvswitchAI | 6/4/2026 | 7/22/2026 | A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. This can cause a denial of service (DoS) via resource exhaustion. | |
| Deferred | Medium (4.3) | 0.37% | — | FOX Currency Switcher ProfessionalAI | 5/28/2026 | 6/17/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled… | |
| Deferred | High (7.1) | 0.25% | — | Realmag777 Wpcs Currency-switcherAI | 5/27/2026 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 WPCS currency-switcher allows DOM-Based XSS.This issue affects WPCS: from n/a through <= 1.3.1. | |
| Awaiting Analysis | Medium (6.8) | 0.47% | — | Cisco Nexus 3000 Series SwitchesAICisco Nexus 9000 Series SwitchesAI | 5/20/2026 | 7/23/2026 | A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This… | |
| Deferred | High (8.8) | 0.52% | — | Account SwitcherAI | 5/20/2026 | 7/24/2026 | The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint using a loose comparison (`!=` instead of `!==`) for secret validation at `app/RestAPI.php:111`, combined with no validation that the secret… | |
| Deferred | High (8.1) | 0.50% | — | FOX Currency Switcher ProfessionalAI | 5/15/2026 | 6/17/2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Deferred | Low (3.2) | 0.11% | — | Sangoma SwitchvoxAI | 5/12/2026 | 6/17/2026 | Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file. | |
| Awaiting Analysis | High (7.2) | 1.1% | — | Hikvision SwitchAI | 5/9/2026 | 7/24/2026 | Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary… | |
| Awaiting Analysis | High (7.7) | 0.39% | — | Cisco 350 Series Managed SwitchesAICisco 350x Series Stackable Managed SwitchesAI | 5/6/2026 | 6/17/2026 | This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a… | |
| Awaiting Analysis | Medium (5.9) | 0.64% | — | Openvswitch Open VswitchAI | 5/5/2026 | 9/1/2026 | A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service… | |
| Awaiting Analysis | Medium (6.5) | 0.66% | — | Openvswitch OVNAI | 4/24/2026 | 6/17/2026 | When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a… |