Vulnerabilities
Summary — last 7 days
New vulnerabilities2,774▲ 13 vs. last week
Critical / high1,289▼ 241 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
403,692 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (7.5) | 0.13% | — | AMD Zynq Ultrascale Plus MpsocAIAMD RfsocAI | 10/5/2026 | 10/6/2026 | Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process.… | |
| Awaiting Analysis | Medium (6) | 0.25% | — | — | 10/5/2026 | 10/6/2026 | A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look like it is coming from a different remote URL than it really is when Git clone is happening. If policy is doing more stricter validation, for example based on… | |
| Awaiting Analysis | Medium (6.8) | 0.14% | — | HP ThinproAI | 10/5/2026 | 10/6/2026 | Previous versions of HP ThinPro (prior to HP ThinPro 8.1 SP10) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.1 SP10, which includes updates to mitigate potential vulnerabilities. Previous versions of HP ThinPro (prior to HP ThinPro 9 SP3) could potentially contain security… | |
| Awaiting Analysis | Critical (9.2) | 0.69% | — | CamundaAI | 10/5/2026 | 10/7/2026 | Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An… | |
| Awaiting Analysis | High (7.3) | 0.14% | — | Canimaan Software ClamxavAI | 10/5/2026 | 10/6/2026 | Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability in the Privileged Helper Tool caused by a race condition and insufficient file validation, allowing a local attacker to execute arbitrary code with system privileges. Fixed in 3.11.1. | |
| Deferred | Medium (6.3) | 0.30% | — | Chainguard ApkoAI | 10/5/2026 | 10/6/2026 | apko allows users to build and publish OCI container images built from apk packages. From version 0.2.0 to before version 1.4.5, UserEntry.Parse and GroupEntry.Parse in pkg/passwd read the UID and GID fields of /etc/passwd and /etc/group entries with strconv.Atoi and convert them to uint32 without a range check. On… | |
| Awaiting Analysis | High (7.1) | 0.21% | — | LangflowAI | 10/5/2026 | 10/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only"… | |
| Undergoing Analysis | Critical (9.9) | 0.59% | — | LangflowAI | 10/5/2026 | 10/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with… | |
| Undergoing Analysis | High (7.1) | 0.25% | — | LangflowAI | 10/5/2026 | 10/8/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow authenticated access to the project identifier in a project-scoped MCP connection but did not authorize the resource URI supplied to resources/read. read_resource forwarded the attacker-controlled URI to… | |
| Undergoing Analysis | Medium (5.4) | 0.18% | — | LangflowAI | 10/5/2026 | 10/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through version 1.7.1, an unauthenticated caller who… | |
| Undergoing Analysis | Critical (9.9) | 0.40% | — | LangflowAILangflow-baseAILangflow LFXAI | 10/5/2026 | 10/9/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server… | |
| Awaiting Analysis | Medium (5.5) | 0.20% | — | Redhat QuayAI | 10/5/2026 | 10/8/2026 | A flaw was found in Quay. When handling build trigger requests, the application incorrectly exposes trigger configuration details containing repository write tokens to global read-only administrative users. An authenticated user with read-only privileges can exploit this flaw by querying the build trigger API to… | |
| Deferred | Low (2.1) | 0.24% | — | Dotnet EshopAI | 10/5/2026 | 10/6/2026 | A security flaw has been discovered in dotnet eShop .NET 8. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component Ordering API. Performing a manipulation of the argument OrderNumber results in improper control of resource identifiers. The attack is possible… | |
| Deferred | Low (2.1) | 0.22% | — | Zoneland O2oaAI | 10/5/2026 | 10/6/2026 | A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_assemble_control/jaxrs/excel/upload/with/url of the component General Module. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack can be launched… | |
| Awaiting Analysis | High (7) | 0.21% | — | Newell Brands Dymo IDAI | 10/5/2026 | 10/6/2026 | Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the… | |
| Awaiting Analysis | Medium (5.1) | 0.15% | — | Newell Brands Dymo IDAI | 10/5/2026 | 10/6/2026 | Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses every recognized job file extension on folder browse. A crafted file on any browsed network share can perform SSRF, capture NTLMv2 credentials, read local files, or… | |
| Deferred | High (8.8) | 0.36% | — | Presstigers Simple Event PlannerAI | 10/5/2026 | 10/6/2026 | Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7. | |
| Deferred | High (7.5) | 0.24% | — | Feehi CMSAI | 10/5/2026 | 10/6/2026 | Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopback or link-local addresses, allowing an attacker to make the server probe internal HTTP services through response differences. | |
| Deferred | Medium (6.5) | 0.53% | — | Feehi CMSAI | 10/5/2026 | 10/6/2026 | Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. Article image metadata is used to construct a filesystem path and is passed to `unlink()` without path traversal or directory validation. | |
| Deferred | High (7.2) | 0.27% | — | Feehi CMSAI | 10/5/2026 | 10/6/2026 | Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update scenario does not require the old password. | |
| Deferred | High (8.2) | 0.30% | — | Ash-rs ASHAI | 10/5/2026 | 10/6/2026 | Ash stores :atom-typed attributes as strings and compares them as strings. When such an attribute is referenced in a filter, the comparison value is coerced through Ash.Type.Atom. Because the type defined no coerce/2 callback, coercion fell back to the default (cast_input/2), which calls String.to_atom/1 when the… | |
| Deferred | High (7.2) | 0.30% | — | Sunshinephotocart Sunshine Photo CartAI | 10/5/2026 | 10/6/2026 | Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1. | |
| Deferred | Medium (6.8) | 0.18% | — | Mercusys Ac12AI | 10/5/2026 | 10/6/2026 | An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the UART serial interface on the printed circuit board (PCB) | |
| Deferred | High (7.7) | 0.14% | — | Mercusys Ac12AI | 10/5/2026 | 10/6/2026 | An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via a hardcoded 512-bit RSA Private Key | |
| Deferred | High (7.8) | 0.08% | — | Mercusys Ac12AI | 10/5/2026 | 10/6/2026 | An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext |