Vulnerabilities

Summary — last 7 days

New vulnerabilities2,768▲ 15 vs. last week
Critical / high1,274▼ 248 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 228 vs. last week
–

403,727 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredCritical (9.9)0.35%—PlaneAI10/5/202610/7/2026
Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original…
DeferredHigh (7.4)0.45%—PlaneAI10/5/202610/5/2026
Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding…
DeferredHigh (8.1)0.29%—PlaneAI10/5/202610/6/2026
Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does…
DeferredMedium (5.5)0.33%—Anisha Online Appointment Booking SystemAI10/5/202610/6/2026
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient Login Handler. The manipulation of the argument uname/psw results in sql injection. It is possible…
DeferredMedium (5.5)0.33%—Onetwothreeneth HospitalmanagementsystemAI10/5/202610/6/2026
A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the function get of the file print.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The…
Awaiting AnalysisLow (2.5)0.22%—CupsAI10/5/202610/7/2026
An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as…
AnalyzedHigh (8.8)0.68%—Apache Struts10/5/202610/8/2026
Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the application-wide text provider is used by concurrently served requests without isolation,…
AnalyzedMedium (6.5)0.69%—Apache Struts10/5/202610/8/2026
Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin. A request body is read into memory without any bound on how much will be accepted, so a single request can cause the server to allocate memory in proportion to its size, exhausting the Java heap and denying service to…
AnalyzedHigh (7.5)0.95%—Apache Struts10/5/202610/8/2026
Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through the Struts tag library, the framework can produce a response many orders of magnitude larger than the…
AnalyzedCritical (9.8)1.2%—Apache Struts10/5/202610/8/2026
Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts…
DeferredCritical (9.3)0.25%—Wp-base WP Base BookingAI10/5/202610/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
DeferredHigh (7.2)0.40%—Rymera WEB CO WOO Product Feed PROAI10/5/202610/6/2026
Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.5.7.
DeferredHigh (7.5)0.32%—Fivestarplugins Five Star Restaurant ReservationsAI10/5/202610/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.24.
DeferredMedium (6.5)0.23%—Ayecode UserswpAI10/5/202610/6/2026
Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74.
DeferredMedium (6.5)0.20%—Wpusermanager WP User ManagerAI10/5/202610/6/2026
Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20.
DeferredMedium (6.5)0.25%—Villatheme LookzyAI10/5/202610/6/2026
Missing Authorization vulnerability in VillaTheme Lookzy woo-lookbook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lookzy: from n/a through 1.1.14.
DeferredHigh (7.1)0.19%—Villatheme Photo Reviews FOR WoocommerceAI10/5/202610/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30.
DeferredMedium (6.5)0.17%—Webfulcreations RepairbuddyAI10/5/202610/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Stored XSS.This issue affects RepairBuddy: from n/a through 4.1225.
Awaiting AnalysisMedium (6.8)0.11%—Moby BuildkitAI10/5/202610/6/2026
The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds…
Awaiting AnalysisMedium (6.9)0.13%—Moby BuildkitAI10/5/202610/6/2026
A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
Awaiting AnalysisMedium (6)0.11%—Moby BuildkitAI10/5/202610/6/2026
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Awaiting AnalysisMedium (5.7)0.09%—Moby BuildkitAI10/5/202610/6/2026
A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.
Awaiting AnalysisHigh (7.5)0.17%—Moby BuildkitAI10/5/202610/6/2026
A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent…
Awaiting AnalysisMedium (5.9)0.16%—Linuxfoundation ContainerdAI10/5/202610/6/2026
An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.
Awaiting AnalysisHigh (7.1)0.24%—Moby BuildkitAI10/5/202610/6/2026
If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.