Vulnerabilities

Summary — last 7 days

New vulnerabilities2,729▼ 127 vs. last week
Critical / high1,241▼ 295 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 201 vs. last week
–

403,497 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisMedium (6.5)0.18%—Cloudfoundry UAAAI10/6/202610/6/2026
Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) allows an authenticated UAA user to bypass the OAuth authorization-code exchange and establish an authenticated external-OIDC browser session, via submitting a UAA access…
Undergoing AnalysisHigh (7.8)0.11%——10/6/202610/6/2026
Memory corruption while processing service requests.
Undergoing AnalysisHigh (7.8)0.11%——10/6/202610/6/2026
Memory Corruption when executing system service routines due to improper handling of user input buffers.
Undergoing AnalysisHigh (7.8)0.11%——10/6/202610/6/2026
Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations.
Undergoing AnalysisHigh (7.5)0.26%——10/6/202610/6/2026
Transient DOS when processing a continuous receive command with a zero-sized global configuration override.
Undergoing AnalysisHigh (7.8)0.12%——10/6/202610/6/2026
Memory corruption when processing draw objects of incorrect type during graphics command list execution.
Undergoing AnalysisHigh (7.8)0.11%——10/6/202610/6/2026
Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization.
Undergoing AnalysisHigh (7.1)0.09%——10/6/202610/6/2026
Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed.
Undergoing AnalysisHigh (7.8)0.11%——10/6/202610/6/2026
Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.
Undergoing AnalysisMedium (6.7)0.11%——10/6/202610/6/2026
Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization.
Undergoing AnalysisMedium (6.7)0.11%——10/6/202610/6/2026
Memory Corruption when processing camera operations due to out-of-bounds write during driver updates.
Undergoing AnalysisMedium (6.7)0.11%——10/6/202610/6/2026
Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation.
Undergoing AnalysisMedium (6.7)0.11%——10/6/202610/6/2026
Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver.
Undergoing AnalysisMedium (6.7)0.11%——10/6/202610/7/2026
Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size.
Undergoing AnalysisHigh (7.8)0.10%——10/6/202610/7/2026
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
Undergoing AnalysisMedium (6.6)0.09%——10/6/202610/6/2026
Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters.
DeferredHigh (8.6)0.48%—Tenda AC5AI10/6/202610/6/2026
A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has…
DeferredMedium (5.5)0.33%——10/6/202610/6/2026
A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible…
DeferredHigh (8.8)0.55%—AcptAI10/6/202610/6/2026
The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for…
DeferredMedium (6.5)0.21%—WP Event SolutionAI10/6/202610/6/2026
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
DeferredHigh (7.2)0.28%—Wpexperts Post SmtpAI10/6/202610/9/2026
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This…
DeferredHigh (7.5)0.24%—SitemovrAI10/6/202610/6/2026
Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
DeferredHigh (7.5)0.26%—Wpsynchro WP SynchroAI10/6/202610/6/2026
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
DeferredHigh (7.5)0.20%—Fluent Affiliate PROAI10/6/202610/6/2026
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
DeferredHigh (7.1)0.15%—Real 3D FlipbookAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.