Vulnerabilities
Summary — last 7 days
New vulnerabilities2,729▼ 513 vs. last week
Critical / high1,298▼ 212 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
610 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (4.4) | 0.25% | — | User Language SwitchAI | 2/14/2026 | 6/17/2026 | The User Language Switch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tab_color_picker_language_switch' parameter in all versions up to, and including, 1.6.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Deferred | High (7.1) | 0.71% | — | Ruijienetworks Switch Eweb S29 RgosAI | 1/29/2026 | 6/17/2026 | The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by manipulating file path parameters. Attackers can exploit the /download.do endpoint with '../' sequences to retrieve system configuration… | |
| Deferred | Medium (6.7) | 0.29% | — | Managed Switch Port Mapping ToolAI | 1/23/2026 | 6/17/2026 | Managed Switch Port Mapping Tool 2.85.2 contains a denial of service vulnerability that allows attackers to crash the application by creating an oversized buffer. Attackers can generate a 10,000-character buffer and paste it into the IP Address and SNMP Community Name fields to trigger the application crash. | |
| Analyzed | Critical (9.8) | 3.9% | ⚠ Active exploitation | Fortinet FortiosFortinet FortiswitchmanagerFortinet FortisaseSiemens Ruggedcom Ape1808 Firmware | 1/13/2026 | 10/7/2026 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized… | |
| Deferred | Medium (4.3) | 0.13% | — | Tikweb Fast User SwitchingAI | 12/24/2025 | 10/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tikweb Management Fast User Switching fast-user-switching allows Cross Site Request Forgery.This issue affects Fast User Switching: from n/a through <= 1.4.10. | |
| Analyzed | Critical (9.8) | 68% | ⚠ Active exploitation💥 PoC | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosSiemens Ruggedcom Ape1808 Firmware | 12/9/2025 | 6/17/2026 | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through… | |
| Analyzed | High (7.1) | 9.8% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 12/9/2025 | 10/7/2026 | An XSS vulnerability in pxc_portSfp.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analyzed | High (7.1) | 9.8% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 12/9/2025 | 10/7/2026 | An XSS vulnerability in pxc_portCntr.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analyzed | High (7.1) | 9.8% | — | Phoenixcontact FL Switch 2008f FirmwarePhoenixcontact FL Switch 2016 FirmwarePhoenixcontact FL Switch 2105 FirmwarePhoenixcontact FL Switch 2108 Firmware+65 | 12/9/2025 | 10/7/2026 | An XSS vulnerability in pxc_PortCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analyzed | High (7.1) | 0.65% | — | Phoenixcontact FL Switch 2008f FirmwarePhoenixcontact FL Switch 2016 FirmwarePhoenixcontact FL Switch 2105 FirmwarePhoenixcontact FL Switch 2108 Firmware+65 | 12/9/2025 | 10/7/2026 | An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analyzed | High (7.1) | 9.8% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 12/9/2025 | 10/7/2026 | An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analyzed | High (7.1) | 9.8% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 12/9/2025 | 10/7/2026 | An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such… | |
| Analyzed | High (7.1) | 9.8% | — | Phoenixcontact FL Switch 2406-2sfx PN FirmwarePhoenixcontact FL Switch 2408 FirmwarePhoenixcontact FL Switch 2408 PN FirmwarePhoenixcontact FL Switch 2412-2tc-2sfx Firmware+65 | 12/9/2025 | 10/7/2026 | An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such… | |
| Analyzed | High (7.1) | 0.65% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 12/9/2025 | 10/7/2026 | An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analyzed | Medium (6.8) | 0.24% | — | Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+65 | 12/9/2025 | 10/7/2026 | An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692. | |
| Analyzed | Medium (4.6) | 0.21% | — | Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+65 | 12/9/2025 | 10/7/2026 | An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device. | |
| Analyzed | High (7.1) | 0.66% | — | Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+65 | 12/9/2025 | 10/7/2026 | An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as… | |
| Analyzed | Medium (6.5) | 0.48% | — | Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+65 | 12/9/2025 | 10/7/2026 | A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more data, resulting in a DoS condition of the websserver. | |
| Analyzed | Medium (4.3) | 0.52% | — | Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+65 | 12/9/2025 | 10/7/2026 | A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not affected. | |
| Analyzed | Medium (6.8) | 0.30% | — | Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+65 | 12/9/2025 | 10/7/2026 | A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm. | |
| Deferred | High (7.7) | 0.14% | — | Mitsubishielectric Milco.s Setting ApplicationAIMitsubishielectric Milco.s Easy Setting ApplicationAIMitsubishielectric Milco.s Easy Switch ApplicationAI | 11/18/2025 | 6/17/2026 | Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S Setting Application all versions, MILCO.S Setting Application (IR) all versions, MILCO.S Easy Setting Application (IR) all versions, and MILCO.S Easy Switch Application (IR) all versions allows a… | |
| Deferred | Medium (5.4) | 0.29% | — | Post Type SwitcherAI | 11/18/2025 | 6/17/2026 | The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.0 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Author-level access and above, to modify the post type of arbitrary posts… | |
| Analyzed | Medium (6.5) | 0.23% | — | Samsung Smart Switch | 11/5/2025 | 6/17/2026 | Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to access backup data from applications. | |
| Deferred | None (0) | 0.18% | — | Moxa Ethernet SwitchesAI | 10/23/2025 | 6/17/2026 | An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially crafted Host header into HTTP requests sent to an affected device’s web service.… | |
| Deferred | Medium (4.8) | 0.33% | — | Moxa Ethernet SwitchesAI | 10/23/2025 | 6/17/2026 | Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attacker to inject malicious scripts to an affected device’s web service that could impact authenticated users interacting with the device’s web interface. This vulnerability is classified as stored… |