Vulnerabilities
Summary — last 7 days
New vulnerabilities2,517▼ 428 vs. last week
Critical / high1,288▲ 1 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)62▼ 465 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Critical (9) | 0.14% | — | Canonical AdsysAISambaAI | 6/22/2026 | 6/22/2026 | An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plaintext HTTP… | |
| Modified | Critical (9.8) | 0.84% | — | Theradsystem Project Theradsystem | 1/17/2023 | 6/17/2026 | A vulnerability was found in saemorris TheRadSystem and classified as critical. This issue affects the function redirect of the file _login.php. The manipulation of the argument user/pass leads to sql injection. The attack may be initiated remotely. The identifier of the patch is… | |
| Modified | Medium (6.1) | 0.51% | — | Theradsystem Project Theradsystem | 1/16/2023 | 6/17/2026 | A vulnerability was found in saemorris TheRadSystem. It has been classified as problematic. Affected is an unknown function of the file users.php. The manipulation of the argument q leads to cross site scripting. It is possible to launch the attack remotely. VDB-218454 is the identifier assigned to this vulnerability. |