Vulnerabilities

Summary — last 7 days

New vulnerabilities3,075▲ 488 vs. last week
Critical / high1,457▲ 57 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedCritical (9.8)100%⚠ Active exploitation💥 ExploitMicrosoft Windows 7Microsoft Windows Server 2008Siemens Axiom Multix M FirmwareSiemens Axiom Vertix MD Trauma Firmware+635/16/20196/17/2026
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
AnalyzedHigh (8.1)96%⚠ Active exploitation💥 ExploitHuawei Agile Controller-campus FirmwareHuawei AnyofficeHuawei LogcenterHuawei Firehunter6000 Firmware+164/26/201610/9/2026
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
ModifiedMedium (6.1)0.76%—Huawei Agile Controller-campus2/8/20166/17/2026
Cross-site scripting (XSS) vulnerability in an unspecified portal authentication page in Huawei Agile Controller-Campus with software before V100R001C00SPC319 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Orbitaley — Vulnerabilities