Vulnerabilities
Summary — last 7 days
New vulnerabilities2,715▼ 529 vs. last week
Critical / high1,290▼ 220 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
610 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.4) | 0.41% | — | Switch CTA BOXAI | 4/22/2026 | 6/17/2026 | The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping on user-supplied post meta values including 'cta_box_button_link', 'cta_box_button_id',… | |
| Modified | Medium (6.5) | 0.50% | — | Fortinet FortiosFortinet FortipamFortinet FortiproxyFortinet Fortiswitchmanager | 4/14/2026 | 6/17/2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all… | |
| Deferred | Low (2.1) | 0.20% | — | Farion1231 Cc-switchAI | 4/13/2026 | 6/17/2026 | A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functionality of the file src-tauri/src/proxy/server.rs of the component ProxyServer. The manipulation results in permissive cross-domain policy with untrusted domains. The attack can be executed remotely.… | |
| Deferred | Medium (5.3) | 0.31% | — | Realmag777 FOX Woocommerce Currency SwitcherAI | 4/8/2026 | 7/24/2026 | Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FOX: from n/a through <= 1.4.5. | |
| Deferred | High (7.6) | 0.38% | — | Realmag777 FOX Woocommerce Currency SwitcherAI | 4/8/2026 | 7/24/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Blind SQL Injection.This issue affects FOX: from n/a through <= 1.4.5. | |
| Awaiting Analysis | Medium (4.6) | 0.24% | — | Aziot Node Smart Switch 16ampAI | 4/6/2026 | 7/5/2026 | An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface. An attacker with physical access can connect to the UART interface and obtain sensitive information from the serial console… | |
| Analyzed | Critical (9.2) | 0.51% | — | Belden Hios Switch | 4/2/2026 | 7/24/2026 | HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot… | |
| Analyzed | Medium (6.8) | 0.29% | — | Eusing Free IP Switcher | 3/30/2026 | 6/17/2026 | Free IP Switcher 3.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Computer Name field. Attackers can paste a malicious payload into the Computer Name input field and click Activate to trigger a denial of service condition… | |
| Analyzed | Medium (5.7) | 0.46% | — | Qnap Qunetswitch | 3/20/2026 | 6/17/2026 | A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later | |
| Analyzed | Medium (6.3) | 0.95% | — | Qnap Qunetswitch | 3/20/2026 | 6/17/2026 | A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later | |
| Analyzed | Medium (6.8) | 0.32% | — | Qnap Qunetswitch | 3/20/2026 | 6/17/2026 | A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later | |
| Analyzed | High (8.1) | 1.1% | — | Qnap Qunetswitch | 3/20/2026 | 6/17/2026 | A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later | |
| Analyzed | High (7.1) | 0.24% | 💥 PoC | Samsung Smart Switch | 3/16/2026 | 6/17/2026 | Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege. | |
| Analyzed | Medium (6.9) | 0.18% | 💥 PoC | Samsung Smart Switch | 3/16/2026 | 6/17/2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service. | |
| Analyzed | High (7.1) | 0.31% | — | Samsung Smart Switch | 3/16/2026 | 6/17/2026 | Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions. | |
| Analyzed | High (7.1) | 0.55% | — | Samsung Smart Switch | 3/16/2026 | 6/17/2026 | Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication. | |
| Analyzed | Medium (5.3) | 0.26% | — | Samsung Smart Switch | 3/16/2026 | 6/17/2026 | Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication. | |
| Analyzed | High (7.1) | 0.17% | — | Samsung Smart Switch | 3/16/2026 | 6/17/2026 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication. | |
| Analyzed | Medium (5.3) | 0.28% | — | Samsung Smart Switch | 3/16/2026 | 6/17/2026 | Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration. | |
| Deferred | Medium (5.3) | 0.26% | — | Woobewoo WBW Currency Switcher FOR WoocommerceAI | 3/13/2026 | 6/17/2026 | Missing Authorization vulnerability in WBW Plugins WBW Currency Switcher for WooCommerce woo-currency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WBW Currency Switcher for WooCommerce: from n/a through <= 2.2.5. | |
| Analyzed | Medium (6.7) | 0.15% | — | Fortinet Fortiswitchaxfixed | 3/10/2026 | 6/17/2026 | An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated admin to execute system commands via a specifically crafted SSH config file. | |
| Analyzed | High (8.8) | 0.30% | — | Fortinet Fortiswitchaxfixed | 3/10/2026 | 6/17/2026 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a crafted LLDP packet. | |
| Deferred | High (7.7) | 0.31% | — | Cisco Nexus 9000 Series Fabric SwitchesAI | 2/25/2026 | 6/17/2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper processing when parsing SNMP… | |
| Deferred | High (7.4) | 0.17% | — | Cisco Nexus 9000 Series Fabric SwitchesAI | 2/25/2026 | 6/17/2026 | A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation when processing specific Ethernet frames. An attacker could exploit this… | |
| Deferred | Medium (5.5) | 0.36% | 💥 PoC | User Language SwitchAI | 2/14/2026 | 6/17/2026 | The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web… |