Vulnerabilities

Summary — last 7 days

New vulnerabilities2,737▼ 486 vs. last week
Critical / high1,302▼ 188 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)227▼ 275 vs. last week
–

52 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.9)0.76%—Simalexan Api-lambda-send-email-sesAI9/13/20269/14/2026
A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing…
DeferredCritical (9.1)0.66%💥 PoCAlexantr FilemanagerAI6/29/20266/30/2026
An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component
DeferredMedium (5.9)0.22%—Alexandre Froger WP WeixinAI9/9/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexandre Froger WP Weixin wp-weixin allows Stored XSS.This issue affects WP Weixin: from n/a through <= 1.3.16.
DeferredHigh (7.1)0.15%—Alexander Rauscha MlanguageAI4/17/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Alexander Rauscha mLanguage mlanguage allows Stored XSS.This issue affects mLanguage: from n/a through <= 1.6.1.
DeferredMedium (6.5)0.28%—Alexander Weleczka Fontawesome.io ShortcodesAI1/16/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexander Weleczka FontAwesome.io ShortCodes allows Stored XSS.This issue affects FontAwesome.io ShortCodes: from n/a through 1.0.
DeferredMedium (4.3)0.43%—Alexander Volkov ChatterAI12/9/20246/17/2026
Missing Authorization vulnerability in Alexander Volkov Chatter.This issue affects Chatter: from n/a through 1.0.1.
DeferredMedium (4.3)0.38%—Alexacrm Dynamics 365 IntegrationAI12/9/20246/17/2026
Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.13.
DeferredMedium (5.4)0.36%—Alexacrm Dynamics 365 IntegrationAI12/9/20246/17/2026
Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.12.
DeferredMedium (6.5)0.26%—Alexandremagno WP AgendaAI11/19/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alexandremagno WP Agenda wp-agenda allows Stored XSS.This issue affects WP Agenda: from n/a through <= 2.0.
DeferredHigh (7.1)0.41%—Jerin K Alexander Events Manager PRO ExtendedAI11/19/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jerin K Alexander Events Manager Pro – extended events-manager-pro-extended allows Reflected XSS.This issue affects Events Manager Pro – extended: from n/a through <= 0.1.
DeferredCritical (9.9)0.52%—Alexander DE Ridder INK OfficialAI10/23/20246/17/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Alexander De Ridder INK Official ink-official allows Upload a Web Shell to a Web Server.This issue affects INK Official: from n/a through <= 4.1.2.
DeferredMedium (5.3)0.58%—Alexacrm Dynamics 365 IntegrationAI5/14/20246/17/2026
Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from n/a through 1.3.17.
DeferredMedium (4.3)0.21%—Perrinalexandre05 AffieasyAI4/15/20246/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in perrinalexandre05 AffiEasy affieasy.This issue affects AffiEasy: from n/a through <= 1.1.4.
ModifiedHigh (8.8)0.23%—Mariosalexandrou Republish OLD Posts1/5/20246/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Republish Old Posts.This issue affects Republish Old Posts: from n/a through 1.21.
ModifiedMedium (6.1)0.39%—Alexanderlivanov Fotoscms210/28/20236/17/2026
A vulnerability classified as problematic was found in AlexanderLivanov FotosCMS2 up to 2.4.3. This vulnerability affects unknown code of the file profile.php of the component Cookie Handler. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has…
ModifiedMedium (5.3)0.59%—Alexanderschneider User Access Manager8/30/20236/17/2026
The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible for attackers to access restricted content in certain situations.
ModifiedHigh (7.6)0.67%—Amazon Alexa5/24/20236/17/2026
Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relevant commands via an audio signal between 16 and 22 kHz (often outside the range of human adult hearing). Commands at these frequencies are essentially never spoken by…
ModifiedHigh (8.8)0.40%—Lenovo Smart Clock Essential With Alexa Built IN Firmware5/1/20236/17/2026
A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with local network access.
ModifiedCritical (9.8)2.7%💥 ExploitAlexandriabooklibrary Alexandria Book Library2/22/20186/17/2026
SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter.
ModifiedMedium (5.4)0.27%—Paulalexanderformayor Paul Alexander Campaign10/16/20146/17/2026
The Paul Alexander Campaign (aka hr.apps.n51261427) application 4.5.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModifiedMedium (4.3)1.1%—Alexander Palmo Simple PHP Blog12/29/20116/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.7.0 and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry parameter to delete.php or (2) category parameter to index.php.
ModifiedHigh (7.5)3.6%—Alexander V. Lukyanov Lftp7/6/20106/16/2026
The get1 command, as used by lftpget, in LFTP before 4.0.6 does not properly validate a server-provided filename before determining the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a Content-Disposition header that suggests a crafted filename, and possibly…
ModifiedMedium (4.3)1.2%💥 ExploitAlexandre Dubus Audistat3/23/20106/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) mday parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModifiedHigh (7.5)0.89%💥 ExploitAlexandre Dubus Audistat3/23/20106/16/2026
Multiple SQL injection vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) month parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModifiedHigh (7.5)0.97%💥 ExploitAlexandre Dubus Audistat3/23/20106/16/2026
SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via the mday parameter.