Vulnerabilities
Summary — last 7 days
New vulnerabilities2,761▲ 61 vs. last week
Critical / high1,285▼ 211 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
403,697 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.5) | 0.27% | — | GhostAI | 10/5/2026 | 10/6/2026 | Ghost is a Node.js content management system. From 5.81.0 until 6.60.0, staff with the Author role could delete posts and pages that they did not author. This issue is fixed in version 6.60.0. | |
| Deferred | High (7.3) | 0.24% | — | GhostAI | 10/5/2026 | 10/6/2026 | Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restriction was not applied, so files uploaded by any staff user were served with a… | |
| Deferred | Medium (4.3) | 0.20% | — | GhostAI | 10/5/2026 | 10/7/2026 | Ghost is a Node.js content management system. From 0.5.0 until 6.64.0, staff users with the Editor or Super Editor role were able to assign their own role to Author and Contributor users, despite not having permission to assign that role. This issue is fixed in version 6.64.0. | |
| Deferred | High (7.2) | 0.52% | — | GhostAI | 10/5/2026 | 10/6/2026 | Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0. | |
| Deferred | Medium (4.9) | 0.40% | — | GhostAI | 10/5/2026 | 10/6/2026 | Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of the active theme's directory, potentially exposing server configuration secrets. This issue is fixed in version 6.64.0. | |
| Deferred | High (7.5) | 0.39% | — | GhostAI | 10/5/2026 | 10/6/2026 | Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than their own. This could allow a staff user to escalate their privileges by accepting… | |
| Deferred | Low (3.1) | 0.26% | — | GhostAI | 10/5/2026 | 10/6/2026 | Ghost is a Node.js content management system. From 0.7.2 until 6.64.0, any staff-level user was able to determine the relative ordering of other staff users' hashed passwords. This does not directly disclose password hashes, and does not provide a practical path to recovering a password. This issue is fixed in version… | |
| Deferred | High (7.3) | 0.30% | — | GhostAI | 10/5/2026 | 10/7/2026 | Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, including Contributors, to host arbitrary HTML on the site's domain, possibly resulting… | |
| Deferred | High (8.1) | 0.33% | — | GhostAI | 10/5/2026 | 10/6/2026 | Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a… | |
| Deferred | High (7.3) | 0.30% | — | GhostAI | 10/5/2026 | 10/6/2026 | Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff… | |
| Deferred | Medium (4) | 0.30% | — | GhostAI | 10/5/2026 | 10/6/2026 | Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network on some network configurations. A successful attack would not… | |
| Deferred | Medium (4) | 0.23% | — | GhostAI | 10/5/2026 | 10/6/2026 | Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data… | |
| Deferred | Medium (5.5) | 0.29% | — | Lybbn Django VUE LyadminAI | 10/5/2026 | 10/6/2026 | A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is… | |
| Deferred | Low (2.1) | 0.21% | — | Feelec-yishu Feelcrm-osAI | 10/5/2026 | 10/7/2026 | A security vulnerability has been detected in feelec-yishu feelcrm-os 1.0.0. This issue affects some unknown processing of the file App/Feelcrm/Crm/Controller/UploadController.class.php of the component UploadTicketFile Endpoint. Such manipulation of the argument cmd leads to unrestricted upload. The attack can be… | |
| Deferred | Low (2.1) | 0.25% | — | Feelec-yishu Feelcrm-osAI | 10/5/2026 | 10/6/2026 | A weakness has been identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function index of the file App/Feelcrm/Index/Controller/MemberController.class.php of the component Member Endpoint. This manipulation of the argument group_id causes sql injection. The attack can be initiated remotely. The… | |
| Undergoing Analysis | Medium (5.5) | 0.12% | — | SssdAI | 10/5/2026 | 10/6/2026 | A flaw was found in sssd. This vulnerability allows a local user to cause a Denial of Service (DoS) by submitting a specially crafted passkey authentication token that lacks null terminators. The authentication service reads past the end of the provided memory buffer, causing the process to crash and disrupting… | |
| Undergoing Analysis | Low (3.3) | 0.10% | — | SssdAI | 10/5/2026 | 10/7/2026 | A flaw was found in SSSD. A local attacker can exploit this vulnerability by sending a specially crafted request to the autofs responder UNIX socket. Due to improper buffer offset calculation during request parsing, the service performs an out-of-bounds memory read. This flaw can cause the autofs responder process to… | |
| Deferred | High (7.2) | 0.37% | — | Smackcoders WP Ultimate ExporterAI | 10/5/2026 | 10/6/2026 | Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0. | |
| Deferred | Medium (6.5) | 0.21% | — | Kirillbdev WC Ukraine ShippingAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2. | |
| Deferred | High (8.5) | 0.26% | — | Wp-base WP Base BookingAI | 10/5/2026 | 10/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0. | |
| Deferred | High (8.8) | 0.36% | — | Vektor-inc VK Google JOB Posting ManagerAI | 10/5/2026 | 10/6/2026 | Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1. | |
| Deferred | High (7.2) | 0.37% | — | Wpspellcheck WP Spell CheckAI | 10/5/2026 | 10/6/2026 | Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1. | |
| Deferred | High (7.1) | 0.22% | — | Webfulcreations RepairbuddyAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through 4.1226. | |
| Deferred | Medium (6.9) | 0.25% | — | Themeisle Hyve LiteAI | 10/5/2026 | 10/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Chatbot for WordPress – Hyve Lite: from n/a through 2.0.2. | |
| Deferred | Medium (6.5) | 0.20% | — | Arraytics TimeticsAI | 10/5/2026 | 10/6/2026 | Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.63. |