Vulnerabilities
Summary — last 7 days
New vulnerabilities2,753▼ 36 vs. last week
Critical / high1,269▼ 264 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)241▲ 206 vs. last week
403,622 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.5) | 0.20% | — | Morning-pro MorningAI | 10/6/2026 | 10/8/2026 | Missing Authorization vulnerability in Green Invoice Morning for WooCommerce wc-gateway-greeninvoice allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Morning for WooCommerce: from n/a through 2.4.1. | |
| Deferred | Medium (4.3) | 0.15% | — | WDS MCP Content ManagerAI | 10/6/2026 | 10/6/2026 | Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions. | |
| Deferred | Medium (6.5) | 0.17% | — | Iato MCPAI | 10/6/2026 | 10/8/2026 | Missing Authorization vulnerability in iatoai IATO MCP iato-mcp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IATO MCP: from n/a through 1.12.0. | |
| Deferred | Medium (6.5) | 0.21% | — | Faktur PROAI | 10/6/2026 | 10/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ZWEISCHNEIDER Faktur Pro for WooCommerce woorechnung allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Faktur Pro for WooCommerce: from n/a through 3.2.2. | |
| Deferred | Low (2.1) | 0.30% | — | Vllm-project VllmAI | 10/6/2026 | 10/9/2026 | A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out… | |
| Deferred | Low (2.1) | 0.27% | — | Evilmartians ImgproxyAI | 10/6/2026 | 10/6/2026 | A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may… | |
| Deferred | High (7.5) | 0.20% | — | Fluentbooking PROAI | 10/6/2026 | 10/6/2026 | Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions. | |
| Deferred | Medium (5.5) | 0.33% | — | UptraceAI | 10/6/2026 | 10/6/2026 | A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Deferred | Low (2.1) | 0.16% | — | Sourcecodester Drug Recommendation SystemAI | 10/6/2026 | 10/6/2026 | A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. | |
| Deferred | Low (2.1) | 0.27% | — | Sourcecodester Drug Recommendation SystemAI | 10/6/2026 | 10/8/2026 | A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be… | |
| Deferred | Medium (5.5) | 0.40% | — | Sourcecodester Drug Recommendation SystemAI | 10/6/2026 | 10/6/2026 | A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Deferred | Low (2) | 0.23% | — | Phpgurukul User Registration Login AND User Management SystemAI | 10/6/2026 | 10/6/2026 | A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect… | |
| Deferred | Low (2.1) | 0.23% | — | Jishenghua JsherpAI | 10/6/2026 | 10/6/2026 | A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The… | |
| Deferred | Low (2) | 0.24% | — | Bladex SpringbladeAI | 10/6/2026 | 10/8/2026 | A vulnerability was determined in chillzhuang SpringBlade up to 5.0.1. This affects an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/RoleController.java of the component User Detail Endpoint. This manipulation of the argument ID causes improper authorization.… | |
| Deferred | Low (2) | 0.23% | — | Bladex SpringbladeAI | 10/6/2026 | 10/6/2026 | A vulnerability was found in chillzhuang SpringBlade up to 5.0.1. The impacted element is an unknown function of the file blade-service/blade-system/src/main/java/org/springblade/system/controller/ParamController.java of the component Parameter Submit Management. The manipulation of the argument initPassword results… | |
| Deferred | Low (2.1) | 0.23% | — | Newbee-ltd Newbee-mallAI | 10/6/2026 | 10/6/2026 | A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be… | |
| Deferred | Low (2.1) | 0.22% | — | Pickmall LilishopAI | 10/6/2026 | 10/6/2026 | A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice List. Such manipulation of the argument memberId leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Deferred | Medium (5.5) | 0.28% | — | Pickmall LilishopAI | 10/6/2026 | 10/8/2026 | A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has… | |
| Deferred | Low (2.1) | 1.1% | — | Yogeshojha RengineAI | 10/6/2026 | 10/6/2026 | A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of the argument Name results in os command injection. The attack can be launched remotely. The exploit… | |
| Deferred | Medium (5.5) | 0.50% | — | Ossrs SRSAI | 10/6/2026 | 10/6/2026 | A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used.… | |
| Deferred | Critical (10) | 2.1% | — | Totolink X6000rAI | 10/6/2026 | 10/6/2026 | A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed… | |
| Deferred | Medium (5.3) | 0.16% | — | PunkAI | 10/6/2026 | 10/6/2026 | Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only… | |
| Undergoing Analysis | Medium (6.2) | 0.12% | — | SssdAI | 10/6/2026 | 10/8/2026 | A flaw was found in sssd. A local attacker can trigger a Denial of Service (DoS) by sending a specially crafted Pluggable Authentication Module (PAM) request when passkey authentication is enabled. Due to a missing state validation check in passkey Kerberos handling, the PAM responder dereferences an uninitialized… | |
| Undergoing Analysis | Medium (5.5) | 0.10% | — | SssdAI | 10/6/2026 | 10/6/2026 | A flaw was found in SSSD. A local attacker with access to the Name Service Switch (NSS) responder UNIX socket can trigger an integer underflow by sending a specially crafted request with an undersized packet header. This issue causes an out-of-bounds memory read during packet parsing, crashing the responder process… | |
| Undergoing Analysis | Medium (5.5) | 0.11% | — | SssdAI | 10/6/2026 | 10/7/2026 | A flaw was found in sssd. A local attacker can cause a Denial of Service (DoS) by sending a crafted Pluggable Authentication Module (PAM) request containing a zero-length authentication token to the responder socket. Due to missing input validation, the service attempts to read beyond buffer boundaries when processing… |