Vulnerabilities
Summary — last 7 days
New vulnerabilities2,819→ no change vs. last week
Critical / high1,469▲ 239 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)83▼ 429 vs. last week
123 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (4.9) | 0.51% | — | Ljapps WP Tripadvisor Review SliderAI | 8/5/2026 | 8/12/2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analyzed | High (8.8) | 0.43% | — | Oracle JD Edwards Enterpriseone Solution Advisor | 7/21/2026 | 8/6/2026 | Vulnerability in the JD Edwards EnterpriseOne Solution Advisor product of Oracle JD Edwards (component: Solution Advisor). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Solution Advisor.… | |
| Deferred | Medium (4.9) | 0.48% | — | Ljapps WP Tripadvisor Review SliderAI | 7/16/2026 | 7/16/2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, 14.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Deferred | Medium (6.4) | 0.33% | — | Reviews Widgets FOR Google Yelp AND TripadvisorAI | 7/6/2026 | 7/7/2026 | The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Shortcode::fbrev()… | |
| Deferred | High (8.5) | 0.18% | — | Network Inventory AdvisorAI | 6/19/2026 | 9/29/2026 | Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attackers to escalate privileges by placing malicious executables in intermediate directories. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with… | |
| Analyzed | Medium (5.3) | 0.24% | — | Netapp Active IQ Config Advisor | 6/3/2026 | 7/22/2026 | Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations. | |
| Deferred | Medium (4.6) | 0.20% | — | Hitachi OPS Center AnalyzerAIHitachi OPS Center Analyzer ViewpointAIHitachi Infrastructure Analytics AdvisorAI | 5/26/2026 | 7/24/2026 | Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint, Hitachi Infrastructure Analytics Advisor (Data Center Analytics, Analytics probe modules). This issue affects Hitachi… | |
| Deferred | Medium (6.5) | 0.22% | — | Ljapps WP Tripadvisor Review SliderAI | 3/25/2026 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP TripAdvisor Review Slider wp-tripadvisor-review-slider allows Stored XSS.This issue affects WP TripAdvisor Review Slider: from n/a through <= 14.1. | |
| Analyzed | Medium (6.1) | 0.16% | — | Hitachi Infrastructure Analytics AdvisorHitachi OPS Center Analyzer | 3/25/2026 | 8/12/2026 | Cross-Site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Analytics probe component), Hitachi Ops Center Analyzer.This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Analyzed | Medium (6.5) | 0.32% | — | Dell Data Protection Advisor | 1/23/2026 | 6/17/2026 | Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a Template Engine vulnerability in the Server. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Deferred | High (7.1) | 0.22% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 12/24/2025 | 6/17/2026 | Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Deferred | High (8.2) | 0.20% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 12/24/2025 | 6/17/2026 | Cross-site Scripting vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.5-00. | |
| Analyzed | Medium (6.7) | 0.14% | — | IBM Transformation Advisor | 9/3/2025 | 6/17/2026 | IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Transformation Advisor Operator Catalog image. | |
| Deferred | Medium (5.9) | 0.22% | — | Kevin Heath Tripadvisor ShortcodeAI | 8/28/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kevin heath Tripadvisor Shortcode tripadvisor-shortcode allows Stored XSS.This issue affects Tripadvisor Shortcode: from n/a through <= 2.2. | |
| Analyzed | High (8.8) | 0.26% | — | AI SEO Link Advisor Project AI SEO Link Advisor | 8/15/2025 | 6/17/2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This issue affects AI SEO Link Advisor: from 0.0.0 before 1.0.6. | |
| Analyzed | Medium (5.5) | 0.14% | — | Dell TechadvisorDell Xtremio Management Server | 7/30/2025 | 6/17/2026 | Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may be able to use the exposed credentials to access the vulnerable… | |
| Analyzed | Medium (5.5) | 0.14% | — | Dell TechadvisorDell Xtremio Management Server | 7/30/2025 | 6/17/2026 | TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may be able to use the exposed credentials… | |
| Analyzed | High (7.5) | 1.7% | — | Mywebsiteadvisor Simple Backup | 7/19/2025 | 6/17/2026 | The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the… | |
| Deferred | Medium (6.5) | 0.17% | — | Hitachi Infrastructure Analytics AdvisorAIHitachi OPS Center AnalyzerAI | 5/16/2025 | 6/17/2026 | Bypass Connection Restriction vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component), Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center Analyzer: from 10.0.0-00 before… | |
| Analyzed | High (8.8) | 0.56% | — | Jenkins Health Advisor BY Cloudbees | 5/14/2025 | 6/17/2026 | Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Jenkins Health Advisor server responses. | |
| Analyzed | Medium (5.4) | 0.15% | — | Intel AdvisorIntel Oneapi Base Toolkit | 5/13/2025 | 6/17/2026 | Uncontrolled search path for some Intel(R) Advisor software may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analyzed | Medium (4.1) | 0.29% | — | IBM Qradar Advisor | 3/18/2025 | 6/17/2026 | IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analyzed | Medium (5.4) | 0.20% | — | Intel AdvisorIntel Oneapi Base Toolkit | 2/12/2025 | 6/17/2026 | Uncontrolled search path for some Intel(R) Advisor software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Deferred | Critical (9.4) | 0.78% | — | Hitachi OPS Center AnalyzerAIHitachi Infrastructure Analytics AdvisorAI | 12/17/2024 | 6/17/2026 | Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics component ).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.3-00;… | |
| Analyzed | Medium (5.4) | 0.12% | — | Intel AdvisorIntel Oneapi Base Toolkit | 8/14/2024 | 6/17/2026 | Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access. |