Vulnerabilities
Summary — last 7 days
New vulnerabilities2,729▼ 127 vs. last week
Critical / high1,241▼ 295 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 201 vs. last week
403,497 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (6.5) | 0.18% | — | Cloudfoundry UAAAI | 10/6/2026 | 10/6/2026 | Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) allows an authenticated UAA user to bypass the OAuth authorization-code exchange and establish an authenticated external-OIDC browser session, via submitting a UAA access… | |
| Undergoing Analysis | High (7.8) | 0.11% | — | — | 10/6/2026 | 10/6/2026 | Memory corruption while processing service requests. | |
| Undergoing Analysis | High (7.8) | 0.11% | — | — | 10/6/2026 | 10/6/2026 | Memory Corruption when executing system service routines due to improper handling of user input buffers. | |
| Undergoing Analysis | High (7.8) | 0.11% | — | — | 10/6/2026 | 10/6/2026 | Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations. | |
| Undergoing Analysis | High (7.5) | 0.26% | — | — | 10/6/2026 | 10/6/2026 | Transient DOS when processing a continuous receive command with a zero-sized global configuration override. | |
| Undergoing Analysis | High (7.8) | 0.12% | — | — | 10/6/2026 | 10/6/2026 | Memory corruption when processing draw objects of incorrect type during graphics command list execution. | |
| Undergoing Analysis | High (7.8) | 0.11% | — | — | 10/6/2026 | 10/6/2026 | Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization. | |
| Undergoing Analysis | High (7.1) | 0.09% | — | — | 10/6/2026 | 10/6/2026 | Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed. | |
| Undergoing Analysis | High (7.8) | 0.11% | — | — | 10/6/2026 | 10/6/2026 | Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms. | |
| Undergoing Analysis | Medium (6.7) | 0.11% | — | — | 10/6/2026 | 10/6/2026 | Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization. | |
| Undergoing Analysis | Medium (6.7) | 0.11% | — | — | 10/6/2026 | 10/6/2026 | Memory Corruption when processing camera operations due to out-of-bounds write during driver updates. | |
| Undergoing Analysis | Medium (6.7) | 0.11% | — | — | 10/6/2026 | 10/6/2026 | Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation. | |
| Undergoing Analysis | Medium (6.7) | 0.11% | — | — | 10/6/2026 | 10/6/2026 | Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver. | |
| Undergoing Analysis | Medium (6.7) | 0.11% | — | — | 10/6/2026 | 10/7/2026 | Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size. | |
| Undergoing Analysis | High (7.8) | 0.10% | — | — | 10/6/2026 | 10/7/2026 | Memory corruption when non-secure loader rewrites page tables before secure memory initialization. | |
| Undergoing Analysis | Medium (6.6) | 0.09% | — | — | 10/6/2026 | 10/6/2026 | Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters. | |
| Deferred | High (8.6) | 0.48% | — | Tenda AC5AI | 10/6/2026 | 10/6/2026 | A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has… | |
| Deferred | Medium (5.5) | 0.33% | — | — | 10/6/2026 | 10/6/2026 | A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible… | |
| Deferred | High (8.8) | 0.55% | — | AcptAI | 10/6/2026 | 10/6/2026 | The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for… | |
| Deferred | Medium (6.5) | 0.21% | — | WP Event SolutionAI | 10/6/2026 | 10/6/2026 | Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. | |
| Deferred | High (7.2) | 0.28% | — | Wpexperts Post SmtpAI | 10/6/2026 | 10/9/2026 | The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This… | |
| Deferred | High (7.5) | 0.24% | — | SitemovrAI | 10/6/2026 | 10/6/2026 | Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. | |
| Deferred | High (7.5) | 0.26% | — | Wpsynchro WP SynchroAI | 10/6/2026 | 10/6/2026 | Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. | |
| Deferred | High (7.5) | 0.20% | — | Fluent Affiliate PROAI | 10/6/2026 | 10/6/2026 | Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. | |
| Deferred | High (7.1) | 0.15% | — | Real 3D FlipbookAI | 10/6/2026 | 10/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. |