Vulnerabilities
Summary — last 7 days
New vulnerabilities2,680▼ 660 vs. last week
Critical / high1,277▼ 279 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)227▼ 275 vs. last week
24 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (1.2) | 0.22% | — | AllegroAI | 7/19/2026 | 7/20/2026 | A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function AssetLastHostname.increment_hostname of the file src/ralph/assets/models/assets.py of the component Hostname Allocation Handler. Executing a manipulation of the argument counter can lead to race… | |
| Deferred | High (7.1) | 0.24% | — | Wphocus MY Auctions AllegroAI | 3/25/2026 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Reflected XSS.This issue affects My auctions allegro: from n/a through <= 3.6.35. | |
| Deferred | High (7.5) | 0.55% | — | Wphocus MY Auctions AllegroAI | 1/22/2026 | 6/17/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows PHP Local File Inclusion.This issue affects My auctions allegro: from n/a through <= 3.6.33. | |
| Deferred | High (7.1) | 0.27% | — | Wphocus MY Auctions AllegroAI | 1/22/2026 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Reflected XSS.This issue affects My auctions allegro: from n/a through <= 3.6.32. | |
| Deferred | Medium (5.4) | 0.13% | — | Wphocus MY Auctions AllegroAI | 12/24/2025 | 10/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Cross Site Request Forgery.This issue affects My auctions allegro: from n/a through <= 3.6.33. | |
| Deferred | Medium (5.9) | 0.21% | — | Wphocus MY Auctions AllegroAI | 12/24/2025 | 10/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Stored XSS.This issue affects My auctions allegro: from n/a through <= 3.6.35. | |
| Deferred | High (8.1) | 0.76% | — | MY Auctions AllegroAI | 12/5/2025 | 9/25/2026 | The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.32 via the 'controller' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those… | |
| Deferred | High (7.5) | 0.32% | — | MY Auctions AllegroAI | 12/5/2025 | 6/17/2026 | The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 3.6.32 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Deferred | High (7.1) | 0.13% | — | Allegro Marketing HPB SEOAI | 10/29/2025 | 10/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflected XSS.This issue affects hpb seo plugin for WordPress: from n/a through <= 3.0.1. | |
| Deferred | Medium (4.9) | 0.30% | — | MY Auctions AllegroAI | 10/11/2025 | 6/17/2026 | The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 3.6.31 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Deferred | High (7.1) | 0.14% | — | Wphocus MY Auctions AllegroAI | 4/14/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Stored XSS.This issue affects My auctions allegro: from n/a through <= 3.6.33. | |
| Deferred | High (8.5) | 0.33% | — | Wphocus MY Auctions AllegroAI | 3/31/2025 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Blind SQL Injection.This issue affects My auctions allegro: from n/a through <= 3.6.20. | |
| Deferred | High (7.1) | 0.26% | — | Wphocus MY Auctions AllegroAI | 1/21/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Reflected XSS.This issue affects My auctions allegro: from n/a through <= 3.6.18. | |
| Deferred | Medium (6.1) | 0.36% | — | MY Auctions AllegroAI | 12/3/2024 | 6/17/2026 | The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.6.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Deferred | Medium (6.8) | 0.26% | — | Ariane Allegro Scenario PlayerAICisco DUOAI | 6/6/2024 | 6/17/2026 | Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensitive information (such as hotel invoice content with PII), and potentially create unauthorized room keys, by entering a guest-search quote character and then accessing the… | |
| Modified | High (8.8) | 0.24% | — | Allegrosoft Rompager | 1/14/2024 | 6/17/2026 | A vulnerability was found in Allegro RomPager 4.01. It has been classified as problematic. Affected is an unknown function of the file usertable.htm?action=delete of the component HTTP POST Request Handler. The manipulation of the argument username leads to cross-site request forgery. It is possible to launch the… | |
| Modified | Medium (5.9) | 0.43% | — | Allegro Bigflow | 4/10/2023 | 6/17/2026 | Allegro Tech BigFlow <1.6 is vulnerable to Missing SSL Certificate Validation. | |
| Modified | Medium (6.5) | 0.59% | — | Liballeg Allegro | 2/3/2023 | 6/17/2026 | Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon. | |
| Modified | High (8.1) | 0.77% | — | Allegro | 12/8/2021 | 6/17/2026 | Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials. | |
| Modified | High (7.8) | 0.30% | — | Allegro | 12/8/2021 | 6/17/2026 | An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking. | |
| Modified | High (10) | 6.1% | — | Allegrosoft Rompager | 12/24/2014 | 6/17/2026 | Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and products, allow remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors related to authorization. | |
| Modified | High (10) | 64% | 💥 PoC | Allegrosoft Rompager | 12/24/2014 | 6/17/2026 | AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability. | |
| Modified | Medium (4.3) | 2.2% | — | Allegrosoft RompagerDlink Dsl-2640rDlink Dsl-2641rHuawei Mt882+3 | 1/16/2014 | 6/17/2026 | Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or… | |
| Modified | High (7.5) | 7.1% | 💥 Exploit | Allegro ROM Pager | 6/1/2000 | 6/16/2026 | Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request. |