Vulnerabilities

Summary — last 7 days

New vulnerabilities2,715▼ 529 vs. last week
Critical / high1,290▼ 220 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
–

610 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.4)0.41%—Switch CTA BOXAI4/22/20266/17/2026
The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping on user-supplied post meta values including 'cta_box_button_link', 'cta_box_button_id',…
ModifiedMedium (6.5)0.50%—Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiswitchmanager4/14/20266/17/2026
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all…
DeferredLow (2.1)0.20%—Farion1231 Cc-switchAI4/13/20266/17/2026
A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functionality of the file src-tauri/src/proxy/server.rs of the component ProxyServer. The manipulation results in permissive cross-domain policy with untrusted domains. The attack can be executed remotely.…
DeferredMedium (5.3)0.31%—Realmag777 FOX Woocommerce Currency SwitcherAI4/8/20267/24/2026
Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FOX: from n/a through <= 1.4.5.
DeferredHigh (7.6)0.38%—Realmag777 FOX Woocommerce Currency SwitcherAI4/8/20267/24/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Blind SQL Injection.This issue affects FOX: from n/a through <= 1.4.5.
Awaiting AnalysisMedium (4.6)0.24%—Aziot Node Smart Switch 16ampAI4/6/20267/5/2026
An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface. An attacker with physical access can connect to the UART interface and obtain sensitive information from the serial console…
AnalyzedCritical (9.2)0.51%—Belden Hios Switch4/2/20267/24/2026
HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot…
AnalyzedMedium (6.8)0.29%—Eusing Free IP Switcher3/30/20266/17/2026
Free IP Switcher 3.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Computer Name field. Attackers can paste a malicious payload into the Computer Name input field and click Activate to trigger a denial of service condition…
AnalyzedMedium (5.7)0.46%—Qnap Qunetswitch3/20/20266/17/2026
A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later
AnalyzedMedium (6.3)0.95%—Qnap Qunetswitch3/20/20266/17/2026
A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later
AnalyzedMedium (6.8)0.32%—Qnap Qunetswitch3/20/20266/17/2026
A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later
AnalyzedHigh (8.1)1.1%—Qnap Qunetswitch3/20/20266/17/2026
A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later
AnalyzedHigh (7.1)0.24%💥 PoCSamsung Smart Switch3/16/20266/17/2026
Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.
AnalyzedMedium (6.9)0.18%💥 PoCSamsung Smart Switch3/16/20266/17/2026
Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.
AnalyzedHigh (7.1)0.31%—Samsung Smart Switch3/16/20266/17/2026
Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.
AnalyzedHigh (7.1)0.55%—Samsung Smart Switch3/16/20266/17/2026
Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.
AnalyzedMedium (5.3)0.26%—Samsung Smart Switch3/16/20266/17/2026
Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.
AnalyzedHigh (7.1)0.17%—Samsung Smart Switch3/16/20266/17/2026
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.
AnalyzedMedium (5.3)0.28%—Samsung Smart Switch3/16/20266/17/2026
Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.
DeferredMedium (5.3)0.26%—Woobewoo WBW Currency Switcher FOR WoocommerceAI3/13/20266/17/2026
Missing Authorization vulnerability in WBW Plugins WBW Currency Switcher for WooCommerce woo-currency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WBW Currency Switcher for WooCommerce: from n/a through <= 2.2.5.
AnalyzedMedium (6.7)0.15%—Fortinet Fortiswitchaxfixed3/10/20266/17/2026
An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system commands via a specifically crafted SSH config file.
AnalyzedHigh (8.8)0.30%—Fortinet Fortiswitchaxfixed3/10/20266/17/2026
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a crafted LLDP packet.
DeferredHigh (7.7)0.31%—Cisco Nexus 9000 Series Fabric SwitchesAI2/25/20266/17/2026
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper processing when parsing SNMP…
DeferredHigh (7.4)0.17%—Cisco Nexus 9000 Series Fabric SwitchesAI2/25/20266/17/2026
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation when processing specific Ethernet frames. An attacker could exploit this…
DeferredMedium (5.5)0.36%💥 PoCUser Language SwitchAI2/14/20266/17/2026
The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web…