Vulnerabilities

Summary — last 7 days

New vulnerabilities3,340▲ 436 vs. last week
Critical / high1,491▲ 179 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 119 vs. last week
–

197 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredCritical (10)0.48%—Chef AutomateAI9/11/20269/18/2026
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
AnalyzedHigh (7)0.28%—Microsoft Power Automate FOR Desktop9/8/20269/29/2026
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
DeferredMedium (5.3)0.35%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI8/20/20268/24/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.
DeferredMedium (6.1)0.36%—Beta Systems Software AG Anow AutomateAI8/18/20269/9/2026
Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code
Undergoing AnalysisMedium (5.4)0.16%—Hardware-aware-automated-machine-learningAI8/11/20268/12/2026
Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may…
DeferredLow (1.9)0.17%—Automateyournetwork McpyatsAI8/9/20268/12/2026
A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried…
DeferredHigh (7.3)0.29%—Sourcecodester Casap Automated Enrollment SystemAI7/29/202610/1/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.
DeferredHigh (7.3)0.29%—Sourcecodester Casap Automated Enrollment SystemAI7/29/202610/1/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.
DeferredHigh (7.3)0.29%—Sourcecodester Casap Automated Enrollment SystemAI7/29/202610/1/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.
DeferredCritical (9.8)0.47%—Sourcecodester Casap Automated Enrollment SystemAI7/29/202610/1/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.
DeferredCritical (9.8)0.47%—Sourcecodester Casap Automated Enrollment SystemAI7/29/202610/1/2026
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.
DeferredLow (2.9)0.40%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI7/3/20267/6/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as…
DeferredLow (2.1)0.37%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI7/3/20267/7/2026
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler. The manipulation of the argument ID leads to authorization bypass. Remote…
DeferredHigh (7.5)0.35%—Checkview Automated TestingAI6/25/20266/29/2026
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
DeferredMedium (6.9)0.28%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI6/17/20266/18/2026
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access controls. Remote exploitation of the attack…
DeferredLow (2.1)0.27%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI6/14/20267/23/2026
A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has…
DeferredLow (2.1)0.42%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI5/26/20267/24/2026
A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be performed from remote.…
DeferredLow (2.1)0.23%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI5/26/20267/24/2026
A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation results in cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been released to the public and may…
AnalyzedHigh (8.8)0.21%—Connectwise Automate5/21/20267/23/2026
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate 2026.5.
AnalyzedMedium (6.5)1.00%—Microsoft Power Automate FOR Desktop5/12/20266/17/2026
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
DeferredMedium (5.5)0.79%—Crocodilestick Calibre-web-automatedAI5/4/20266/17/2026
A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been…
DeferredLow (2.1)0.46%—Crocodilestick Calibre-web-automatedAI5/4/20266/17/2026
A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token of the file cps/kobo_auth.py of the component Kobo auth-token Route. The manipulation results in improper authorization. The attack may be performed from remote. The…
DeferredLow (2.1)0.45%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI4/29/20266/17/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results in cross site…
AnalyzedHigh (7.1)0.13%—Connectwise Automate4/20/20266/17/2026
ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based interception of Solution Center traffic in Automate…
DeferredMedium (5.3)0.26%—Nfusionsolutions Precious Metals Automated Product Pricing PROAI4/8/20267/24/2026
Missing Authorization vulnerability in nfusionsolutions Precious Metals Automated Product Pricing – Pro precious-metals-automated-product-pricing-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Precious Metals Automated Product Pricing – Pro: from n/a through <= 4.0.5.