Vulnerabilities

Summary — last 7 days

New vulnerabilities2,714▼ 164 vs. last week
Critical / high1,235▼ 317 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)257▲ 221 vs. last week
–

403,520 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.5)0.17%—Iato MCPAI10/6/202610/8/2026
Missing Authorization vulnerability in iatoai IATO MCP iato-mcp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IATO MCP: from n/a through 1.12.0.
DeferredMedium (6.5)0.21%—Faktur PROAI10/6/202610/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in ZWEISCHNEIDER Faktur Pro for WooCommerce woorechnung allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Faktur Pro for WooCommerce: from n/a through 3.2.2.
DeferredLow (2.1)0.30%—Vllm-project VllmAI10/6/202610/9/2026
A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out…
DeferredLow (2.1)0.27%—Evilmartians ImgproxyAI10/6/202610/6/2026
A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may…
DeferredHigh (7.5)0.20%—Fluentbooking PROAI10/6/202610/6/2026
Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
DeferredMedium (5.5)0.33%—UptraceAI10/6/202610/6/2026
A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed…
DeferredLow (2.1)0.16%—Sourcecodester Drug Recommendation SystemAI10/6/202610/6/2026
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
DeferredLow (2.1)0.27%—Sourcecodester Drug Recommendation SystemAI10/6/202610/8/2026
A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be…
DeferredMedium (5.5)0.40%—Sourcecodester Drug Recommendation SystemAI10/6/202610/6/2026
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used.
DeferredLow (2)0.23%—Phpgurukul User Registration Login AND User Management SystemAI10/6/202610/6/2026
A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect…
DeferredLow (2.1)0.23%—Jishenghua JsherpAI10/6/202610/6/2026
A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The…
DeferredLow (2)0.24%—Bladex SpringbladeAI10/6/202610/8/2026
A vulnerability was determined in chillzhuang SpringBlade up to 5.0.1. This affects an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/RoleController.java of the component User Detail Endpoint. This manipulation of the argument ID causes improper authorization.…
DeferredLow (2)0.23%—Bladex SpringbladeAI10/6/202610/6/2026
A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted element is an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/ParamController.java of the component Parameter Submit Management. The manipulation of the argument initPassword results…
DeferredLow (2.1)0.23%—Newbee-ltd Newbee-mallAI10/6/202610/6/2026
A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be…
DeferredLow (2.1)0.22%—Pickmall LilishopAI10/6/202610/6/2026
A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice List. Such manipulation of the argument memberId leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed…
DeferredMedium (5.5)0.28%—Pickmall LilishopAI10/6/202610/8/2026
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has…
DeferredLow (2.1)1.1%—Yogeshojha RengineAI10/6/202610/6/2026
A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of the argument Name results in os command injection. The attack can be launched remotely. The exploit…
DeferredMedium (5.5)0.50%—Ossrs SRSAI10/6/202610/6/2026
A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used.…
DeferredCritical (10)2.1%—Totolink X6000rAI10/6/202610/6/2026
A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed…
DeferredMedium (5.3)0.16%—PunkAI10/6/202610/6/2026
Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only…
Undergoing AnalysisMedium (6.2)0.12%—SssdAI10/6/202610/8/2026
A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled. Due to a missing state validation check in passkey Kerberos handling, the PAM responder dereferences an uninitialized…
Undergoing AnalysisMedium (5.5)0.10%—SssdAI10/6/202610/6/2026
A flaw was found in SSSD. A local attacker with access to the Name Service Switch (NSS) responder UNIX socket can trigger an integer underflow by sending a specially crafted request with an undersized packet header. This issue causes an out-of-bounds memory read during packet parsing, crashing the responder process…
Undergoing AnalysisMedium (5.5)0.11%—SssdAI10/6/202610/7/2026
A flaw was found in sssd. A local attacker can cause a Denial of Service (DoS) by sending a crafted Pluggable Authentication Module (PAM) request containing a zero-length authentication token to the responder socket. Due to missing input validation, the service attempts to read beyond buffer boundaries when processing…
Undergoing AnalysisMedium (5.5)0.10%—SssdAI10/6/202610/6/2026
A flaw was found in SSSD. An unprivileged local user can repeatedly request lookups for nonexistent entries through the Name Service Switch (NSS) responder. Because the negative cache does not limit the total number of stored entries and only removes expired records when an existing key is rechecked, the cache can…
Undergoing AnalysisMedium (4.4)0.10%—SssdAI10/6/202610/6/2026
A flaw was found in SSSD. When configured with the Entra ID identity provider, input lookup names containing single quotes are not properly escaped before being included in Microsoft Graph Open Data Protocol (OData) queries. A low-privileged local user can exploit this flaw by submitting a crafted search request,…