Vulnerabilities
Summary — last 7 days
New vulnerabilities2,771▼ 1 vs. last week
Critical / high1,280▼ 248 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 211 vs. last week
403,659 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (6.7) | 0.11% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm Cologne FirmwareQualcomm Cq2390m FirmwareQualcomm Cq2390s Firmware+152 | 10/6/2026 | 10/9/2026 | Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size. | |
| Analyzed | High (7.8) | 0.10% | — | Qualcomm Qca6698au FirmwareQualcomm Qca6797aq FirmwareQualcomm Qcc710 FirmwareQualcomm Qcm2290 Firmware+162 | 10/6/2026 | 10/9/2026 | Memory corruption when non-secure loader rewrites page tables before secure memory initialization. | |
| Analyzed | Medium (6.6) | 0.09% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9205s Modem Firmware+162 | 10/6/2026 | 10/9/2026 | Memory corruption while processing IOCTL command called from user space to the kernel with invalid parameters. | |
| Deferred | High (8.6) | 0.48% | — | Tenda AC5AI | 10/6/2026 | 10/6/2026 | A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has… | |
| Deferred | Medium (5.5) | 0.33% | — | — | 10/6/2026 | 10/6/2026 | A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible… | |
| Deferred | High (8.8) | 0.55% | — | AcptAI | 10/6/2026 | 10/6/2026 | The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for… | |
| Deferred | Medium (6.5) | 0.21% | — | WP Event SolutionAI | 10/6/2026 | 10/6/2026 | Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. | |
| Deferred | High (7.2) | 0.28% | — | Wpexperts Post SmtpAI | 10/6/2026 | 10/9/2026 | The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This… | |
| Deferred | High (7.5) | 0.24% | — | SitemovrAI | 10/6/2026 | 10/6/2026 | Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. | |
| Deferred | High (7.5) | 0.26% | — | Wpsynchro WP SynchroAI | 10/6/2026 | 10/6/2026 | Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. | |
| Deferred | High (7.5) | 0.20% | — | Fluent Affiliate PROAI | 10/6/2026 | 10/6/2026 | Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. | |
| Deferred | High (7.1) | 0.15% | — | Real 3D FlipbookAI | 10/6/2026 | 10/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. | |
| Deferred | High (7.5) | 0.20% | — | Morning-pro MorningAI | 10/6/2026 | 10/8/2026 | Missing Authorization vulnerability in Green Invoice Morning for WooCommerce wc-gateway-greeninvoice allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Morning for WooCommerce: from n/a through 2.4.1. | |
| Deferred | Medium (4.3) | 0.15% | — | WDS MCP Content ManagerAI | 10/6/2026 | 10/6/2026 | Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions. | |
| Deferred | Medium (6.5) | 0.17% | — | Iato MCPAI | 10/6/2026 | 10/8/2026 | Missing Authorization vulnerability in iatoai IATO MCP iato-mcp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IATO MCP: from n/a through 1.12.0. | |
| Deferred | Medium (6.5) | 0.21% | — | Faktur PROAI | 10/6/2026 | 10/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ZWEISCHNEIDER Faktur Pro for WooCommerce woorechnung allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Faktur Pro for WooCommerce: from n/a through 3.2.2. | |
| Deferred | Low (2.1) | 0.30% | — | Vllm-project VllmAI | 10/6/2026 | 10/9/2026 | A security vulnerability has been detected in vllm-project vLLM up to 0.31.0. This impacts the function conv_ssm_forward of the file vllm/model_executor/layers/mamba/mamba_mixer2.py of the component Completions Request Handler. The manipulation leads to out-of-bounds read. The attack is possible to be carried out… | |
| Deferred | Low (2.1) | 0.27% | — | Evilmartians ImgproxyAI | 10/6/2026 | 10/6/2026 | A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may… | |
| Deferred | High (7.5) | 0.20% | — | Fluentbooking PROAI | 10/6/2026 | 10/6/2026 | Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions. | |
| Deferred | Medium (5.5) | 0.33% | — | UptraceAI | 10/6/2026 | 10/6/2026 | A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Deferred | Low (2.1) | 0.16% | — | Sourcecodester Drug Recommendation SystemAI | 10/6/2026 | 10/6/2026 | A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. | |
| Deferred | Low (2.1) | 0.27% | — | Sourcecodester Drug Recommendation SystemAI | 10/6/2026 | 10/8/2026 | A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file Admin/add_drug.php. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be… | |
| Deferred | Medium (5.5) | 0.40% | — | Sourcecodester Drug Recommendation SystemAI | 10/6/2026 | 10/6/2026 | A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Deferred | Low (2) | 0.23% | — | Phpgurukul User Registration Login AND User Management SystemAI | 10/6/2026 | 10/6/2026 | A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect… | |
| Deferred | Low (2.1) | 0.23% | — | Jishenghua JsherpAI | 10/6/2026 | 10/6/2026 | A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component Financial Receipt Update Handler. Performing a manipulation results in improper authorization. The… |