Vulnerabilities

Summary — last 7 days

New vulnerabilities2,774▲ 13 vs. last week
Critical / high1,289▼ 241 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
–

403,692 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (7.5)0.13%—AMD Zynq Ultrascale Plus MpsocAIAMD RfsocAI10/5/202610/6/2026
Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process.…
Awaiting AnalysisMedium (6)0.25%——10/5/202610/6/2026
A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look like it is coming from a different remote URL than it really is when Git clone is happening. If policy is doing more stricter validation, for example based on…
Awaiting AnalysisMedium (6.8)0.14%—HP ThinproAI10/5/202610/6/2026
Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.1 SP10, which includes updates to mitigate potential vulnerabilities. Previous versions of HP ThinPro (prior to HP ThinPro 9 SP3) could potentially contain security…
Awaiting AnalysisCritical (9.2)0.69%—CamundaAI10/5/202610/7/2026
Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An…
Awaiting AnalysisHigh (7.3)0.14%—Canimaan Software ClamxavAI10/5/202610/6/2026
Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability in the Privileged Helper Tool caused by a race condition and insufficient file validation, allowing a local attacker to execute arbitrary code with system privileges. Fixed in 3.11.1.
DeferredMedium (6.3)0.30%—Chainguard ApkoAI10/5/202610/6/2026
apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5, UserEntry.Parse and GroupEntry.Parse in pkg/passwd read the UID and GID fields of /etc/passwd and /etc/group entries with strconv.Atoi and convert them to uint32 without a range check. On…
Awaiting AnalysisHigh (7.1)0.21%—LangflowAI10/5/202610/6/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only"…
Undergoing AnalysisCritical (9.9)0.59%—LangflowAI10/5/202610/6/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with…
Undergoing AnalysisHigh (7.1)0.25%—LangflowAI10/5/202610/8/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow authenticated access to the project identifier in a project-scoped MCP connection but did not authorize the resource URI supplied to resources/read. read_resource forwarded the attacker-controlled URI to…
Undergoing AnalysisMedium (5.4)0.18%—LangflowAI10/5/202610/6/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through version 1.7.1, an unauthenticated caller who…
Undergoing AnalysisCritical (9.9)0.40%—LangflowAILangflow-baseAILangflow LFXAI10/5/202610/9/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server…
Awaiting AnalysisMedium (5.5)0.20%—Redhat QuayAI10/5/202610/8/2026
A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to…
DeferredLow (2.1)0.24%—Dotnet EshopAI10/5/202610/6/2026
A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component Ordering API. Performing a manipulation of the argument OrderNumber results in improper control of resource identifiers. The attack is possible…
DeferredLow (2.1)0.22%—Zoneland O2oaAI10/5/202610/6/2026
A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_assemble_control/jaxrs/excel/upload/with/url of the component General Module. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack can be launched…
Awaiting AnalysisHigh (7)0.21%—Newell Brands Dymo IDAI10/5/202610/6/2026
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the…
Awaiting AnalysisMedium (5.1)0.15%—Newell Brands Dymo IDAI10/5/202610/6/2026
Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses every recognized job file extension on folder browse. A crafted file on any browsed network share can perform SSRF, capture NTLMv2 credentials, read local files, or…
DeferredHigh (8.8)0.36%—Presstigers Simple Event PlannerAI10/5/202610/6/2026
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
DeferredHigh (7.5)0.24%—Feehi CMSAI10/5/202610/6/2026
Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopback or link-local addresses, allowing an attacker to make the server probe internal HTTP services through response differences.
DeferredMedium (6.5)0.53%—Feehi CMSAI10/5/202610/6/2026
Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. Article image metadata is used to construct a filesystem path and is passed to `unlink()` without path traversal or directory validation.
DeferredHigh (7.2)0.27%—Feehi CMSAI10/5/202610/6/2026
Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update scenario does not require the old password.
DeferredHigh (8.2)0.30%—Ash-rs ASHAI10/5/202610/6/2026
Ash stores :atom-typed attributes as strings and compares them as strings. When such an attribute is referenced in a filter, the comparison value is coerced through Ash.Type.Atom. Because the type defined no coerce/2 callback, coercion fell back to the default (cast_input/2), which calls String.to_atom/1 when the…
DeferredHigh (7.2)0.30%—Sunshinephotocart Sunshine Photo CartAI10/5/202610/6/2026
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.
DeferredMedium (6.8)0.18%—Mercusys Ac12AI10/5/202610/6/2026
An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the UART serial interface on the printed circuit board (PCB)
DeferredHigh (7.7)0.14%—Mercusys Ac12AI10/5/202610/6/2026
An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via a hardcoded 512-bit RSA Private Key
DeferredHigh (7.8)0.08%—Mercusys Ac12AI10/5/202610/6/2026
An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext