Vulnerabilities

Summary — last 7 days

New vulnerabilities2,759▼ 357 vs. last week
Critical / high1,278▼ 254 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
–

403,392 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Undergoing AnalysisHigh (7.8)0.12%——10/6/202610/6/2026
Memory corruption when processing draw objects of incorrect type during graphics command list execution.
Undergoing AnalysisHigh (7.8)0.11%——10/6/202610/6/2026
Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization.
Undergoing AnalysisHigh (7.1)0.09%——10/6/202610/6/2026
Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed.
Undergoing AnalysisHigh (7.8)0.11%——10/6/202610/6/2026
Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.
Undergoing AnalysisMedium (6.7)0.11%——10/6/202610/6/2026
Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization.
Undergoing AnalysisMedium (6.7)0.11%——10/6/202610/6/2026
Memory Corruption when processing camera operations due to out-of-bounds write during driver updates.
Undergoing AnalysisMedium (6.7)0.11%——10/6/202610/6/2026
Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation.
Undergoing AnalysisMedium (6.7)0.11%——10/6/202610/6/2026
Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver.
Undergoing AnalysisMedium (6.7)0.11%——10/6/202610/7/2026
Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size.
Undergoing AnalysisHigh (7.8)0.10%——10/6/202610/7/2026
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
Undergoing AnalysisMedium (6.6)0.09%——10/6/202610/6/2026
Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters.
DeferredHigh (8.6)0.48%—Tenda AC5AI10/6/202610/6/2026
A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has…
DeferredMedium (5.5)0.33%——10/6/202610/6/2026
A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible…
DeferredHigh (8.8)0.55%—AcptAI10/6/202610/6/2026
The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for…
DeferredMedium (6.5)0.21%—WP Event SolutionAI10/6/202610/6/2026
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
DeferredHigh (7.2)0.28%—Wpexperts Post SmtpAI10/6/202610/9/2026
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This…
DeferredHigh (7.5)0.24%—SitemovrAI10/6/202610/6/2026
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
DeferredHigh (7.5)0.26%—Wpsynchro WP SynchroAI10/6/202610/6/2026
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
DeferredHigh (7.5)0.20%—Fluent Affiliate PROAI10/6/202610/6/2026
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
DeferredHigh (7.1)0.15%—Real 3D FlipbookAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
DeferredHigh (7.5)0.20%—Morning-pro MorningAI10/6/202610/8/2026
Missing Authorization vulnerability in Green Invoice Morning for WooCommerce wc-gateway-greeninvoice allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Morning for WooCommerce: from n/a through 2.4.1.
DeferredMedium (4.3)0.15%—WDS MCP Content ManagerAI10/6/202610/6/2026
Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.
DeferredMedium (6.5)0.17%—Iato MCPAI10/6/202610/8/2026
Missing Authorization vulnerability in iatoai IATO MCP iato-mcp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IATO MCP: from n/a through 1.12.0.
DeferredMedium (6.5)0.21%—Faktur PROAI10/6/202610/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in ZWEISCHNEIDER Faktur Pro for WooCommerce woorechnung allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Faktur Pro for WooCommerce: from n/a through 3.2.2.
DeferredLow (2.1)0.30%—Vllm-project VllmAI10/6/202610/9/2026
A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out…