Vulnerabilities

Summary — last 7 days

New vulnerabilities2,851▼ 221 vs. last week
Critical / high1,331▼ 168 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
–

11 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (8.5)0.15%—Lenovo Accessories AND Display Manager FOR EnterpriseAI8/13/20268/24/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Awaiting AnalysisHigh (7.3)0.13%—HP Accessory WMI ProviderAIHP Docking StationAI6/24/20266/26/2026
A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or arbitrary code execution. HP is releasing software updates to mitigate the potential vulnerability.
Awaiting AnalysisHigh (8.5)0.15%—Lenovo Accessories AND Display Manager FOR EnterpriseAI6/10/20266/17/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
DeferredHigh (8.1)0.84%—Zagg Electronics AccessoriesAI6/14/20256/17/2026
The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.1 via the load_view() function that is called via at least three AJAX actions: 'load_more_post', 'load_shop', and 'load_more_product. This makes it…
DeferredHigh (7.8)0.16%—Lenovo Display Control CenterAILenovo Accessories AND Display ManagerAI8/16/20246/17/2026
An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges to kernel.
DeferredHigh (7.8)0.16%—Lenovo Display Control CenterAILenovo Accessories AND Display ManagerAI8/16/20246/17/2026
An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges.
DeferredHigh (8.1)0.56%—Byondreal AccessorAI6/17/20246/17/2026
A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/accessor/index.
ModifiedCritical (9.8)0.61%—Prestamonster Multi Accessories PRO2/9/20246/17/2026
SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAccessoriesByIdProducts().
ModifiedHigh (7.5)1.2%—Unsafe Accessor Project Unsafe Accessor7/11/20226/17/2026
UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a named module, the internal data of UA is protected by JVM and others can only access UA via UA's standard API. The main application can set up `SecurityCheck.AccessLimiter` for UA to limit access to UA.…
ModifiedHigh (7.5)0.95%💥 ExploitWebsitesrus Accessories ME PHP Affiliate Script8/25/20106/16/2026
SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute arbitrary SQL commands via the Go parameter.
ModifiedMedium (4.3)1.3%💥 ExploitWebsitesrus Accessories ME PHP Affiliate Script8/25/20106/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Keywords parameter to search.php and (2) SearchIndex parameter to browse.php.