Vulnerabilities
Summary — last 7 days
New vulnerabilities2,851▼ 221 vs. last week
Critical / high1,331▼ 168 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
11 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (8.5) | 0.15% | — | Lenovo Accessories AND Display Manager FOR EnterpriseAI | 8/13/2026 | 8/24/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Awaiting Analysis | High (7.3) | 0.13% | — | HP Accessory WMI ProviderAIHP Docking StationAI | 6/24/2026 | 6/26/2026 | A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or arbitrary code execution. HP is releasing software updates to mitigate the potential vulnerability. | |
| Awaiting Analysis | High (8.5) | 0.15% | — | Lenovo Accessories AND Display Manager FOR EnterpriseAI | 6/10/2026 | 6/17/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Deferred | High (8.1) | 0.84% | — | Zagg Electronics AccessoriesAI | 6/14/2025 | 6/17/2026 | The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.1 via the load_view() function that is called via at least three AJAX actions: 'load_more_post', 'load_shop', and 'load_more_product. This makes it… | |
| Deferred | High (7.8) | 0.16% | — | Lenovo Display Control CenterAILenovo Accessories AND Display ManagerAI | 8/16/2024 | 6/17/2026 | An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges to kernel. | |
| Deferred | High (7.8) | 0.16% | — | Lenovo Display Control CenterAILenovo Accessories AND Display ManagerAI | 8/16/2024 | 6/17/2026 | An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM) that could allow a local attacker to escalate privileges. | |
| Deferred | High (8.1) | 0.56% | — | Byondreal AccessorAI | 6/17/2024 | 6/17/2026 | A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/accessor/index. | |
| Modified | Critical (9.8) | 0.61% | — | Prestamonster Multi Accessories PRO | 2/9/2024 | 6/17/2026 | SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAccessoriesByIdProducts(). | |
| Modified | High (7.5) | 1.2% | — | Unsafe Accessor Project Unsafe Accessor | 7/11/2022 | 6/17/2026 | UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a named module, the internal data of UA is protected by JVM and others can only access UA via UA's standard API. The main application can set up `SecurityCheck.AccessLimiter` for UA to limit access to UA.… | |
| Modified | High (7.5) | 0.95% | 💥 Exploit | Websitesrus Accessories ME PHP Affiliate Script | 8/25/2010 | 6/16/2026 | SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute arbitrary SQL commands via the Go parameter. | |
| Modified | Medium (4.3) | 1.3% | 💥 Exploit | Websitesrus Accessories ME PHP Affiliate Script | 8/25/2010 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Keywords parameter to search.php and (2) SearchIndex parameter to browse.php. |