Vulnerabilities
Summary — last 7 days
New vulnerabilities3,340▲ 436 vs. last week
Critical / high1,491▲ 179 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 119 vs. last week
197 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (10) | 0.48% | — | Chef AutomateAI | 9/11/2026 | 9/18/2026 | A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions. | |
| Analyzed | High (7) | 0.28% | — | Microsoft Power Automate FOR Desktop | 9/8/2026 | 9/29/2026 | Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally. | |
| Deferred | Medium (5.3) | 0.35% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 8/20/2026 | 8/24/2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely. | |
| Deferred | Medium (6.1) | 0.36% | — | Beta Systems Software AG Anow AutomateAI | 8/18/2026 | 9/9/2026 | Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code | |
| Undergoing Analysis | Medium (5.4) | 0.16% | — | Hardware-aware-automated-machine-learningAI | 8/11/2026 | 8/12/2026 | Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Deferred | Low (1.9) | 0.17% | — | Automateyournetwork McpyatsAI | 8/9/2026 | 8/12/2026 | A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried… | |
| Deferred | High (7.3) | 0.29% | — | Sourcecodester Casap Automated Enrollment SystemAI | 7/29/2026 | 10/1/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status. | |
| Deferred | High (7.3) | 0.29% | — | Sourcecodester Casap Automated Enrollment SystemAI | 7/29/2026 | 10/1/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class. | |
| Deferred | High (7.3) | 0.29% | — | Sourcecodester Casap Automated Enrollment SystemAI | 7/29/2026 | 10/1/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password. | |
| Deferred | Critical (9.8) | 0.47% | — | Sourcecodester Casap Automated Enrollment SystemAI | 7/29/2026 | 10/1/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class. | |
| Deferred | Critical (9.8) | 0.47% | — | Sourcecodester Casap Automated Enrollment SystemAI | 7/29/2026 | 10/1/2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name. | |
| Deferred | Low (2.9) | 0.40% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 7/3/2026 | 7/6/2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as… | |
| Deferred | Low (2.1) | 0.37% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 7/3/2026 | 7/7/2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler. The manipulation of the argument ID leads to authorization bypass. Remote… | |
| Deferred | High (7.5) | 0.35% | — | Checkview Automated TestingAI | 6/25/2026 | 6/29/2026 | Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions. | |
| Deferred | Medium (6.9) | 0.28% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 6/17/2026 | 6/18/2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access controls. Remote exploitation of the attack… | |
| Deferred | Low (2.1) | 0.27% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 6/14/2026 | 7/23/2026 | A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has… | |
| Deferred | Low (2.1) | 0.42% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 5/26/2026 | 7/24/2026 | A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be performed from remote.… | |
| Deferred | Low (2.1) | 0.23% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 5/26/2026 | 7/24/2026 | A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been released to the public and may… | |
| Analyzed | High (8.8) | 0.21% | — | Connectwise Automate | 5/21/2026 | 7/23/2026 | The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5. | |
| Analyzed | Medium (6.5) | 1.00% | — | Microsoft Power Automate FOR Desktop | 5/12/2026 | 6/17/2026 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network. | |
| Deferred | Medium (5.5) | 0.79% | — | Crocodilestick Calibre-web-automatedAI | 5/4/2026 | 6/17/2026 | A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been… | |
| Deferred | Low (2.1) | 0.46% | — | Crocodilestick Calibre-web-automatedAI | 5/4/2026 | 6/17/2026 | A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token of the file cps/kobo_auth.py of the component Kobo auth-token Route. The manipulation results in improper authorization. The attack may be performed from remote. The… | |
| Deferred | Low (2.1) | 0.45% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 4/29/2026 | 6/17/2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results in cross site… | |
| Analyzed | High (7.1) | 0.13% | — | Connectwise Automate | 4/20/2026 | 6/17/2026 | ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based interception of Solution Center traffic in Automate… | |
| Deferred | Medium (5.3) | 0.26% | — | Nfusionsolutions Precious Metals Automated Product Pricing PROAI | 4/8/2026 | 7/24/2026 | Missing Authorization vulnerability in nfusionsolutions Precious Metals Automated Product Pricing – Pro precious-metals-automated-product-pricing-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Precious Metals Automated Product Pricing – Pro: from n/a through <= 4.0.5. |