Vulnerabilities
Summary — last 7 days
New vulnerabilities2,699▼ 343 vs. last week
Critical / high1,270▼ 197 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)208▼ 123 vs. last week
22 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.1) | 0.50% | — | Digitalbazaar Forge | 3/27/2026 | 9/4/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows… | |
| Modified | High (7.5) | 0.47% | — | Digitalbazaar Forge | 3/27/2026 | 9/4/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signature and its `S + L` variant both… | |
| Modified | High (7.5) | 0.45% | — | Digitalbazaar Forge | 3/27/2026 | 9/10/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing “garbage” bytes within the ASN structure in… | |
| Modified | High (7.5) | 0.90% | — | Digitalbazaar Forge | 3/27/2026 | 9/4/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When… | |
| Deferred | Critical (9.4) | 0.36% | — | Pluginbazaar Order Listener FOR WoocommerceAI | 1/22/2026 | 6/17/2026 | Missing Authorization vulnerability in StackWC Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Listener for WooCommerce: from n/a through <= 3.6.1. | |
| Analyzed | High (8.7) | 0.43% | — | Digitalbazaar Forge | 11/26/2025 | 6/17/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a… | |
| Analyzed | Medium (6.3) | 0.32% | — | Digitalbazaar Forge | 11/26/2025 | 6/17/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller,… | |
| Analyzed | High (8.6) | 0.74% | — | Digitalbazaar Forge | 11/25/2025 | 6/17/2026 | An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions. | |
| Deferred | Critical (9.8) | 0.69% | — | Cafebazaar HODAI | 7/1/2024 | 6/17/2026 | cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Deferred | Medium (4.3) | 0.44% | — | Digitalbazaar ZcapAI | 4/10/2024 | 6/17/2026 | `@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.1, when invoking a capability with a chain depth of 2, i.e., it is delegated directly from the root capability, the `expires` property is not properly checked against the current date or other `date`… | |
| Modified | Medium (6.1) | 1.0% | 💥 Exploit | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 9/4/2023 | 6/17/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modified | Medium (5.3) | 0.30% | — | Jenkins Bazaar | 7/26/2023 | 6/17/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete previously created Bazaar SCM tags. | |
| Modified | Critical (9.8) | 9.9% | 💥 Exploit | Pluginbazaar Order Listener FOR Woocommerce | 5/9/2022 | 6/17/2026 | The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection | |
| Modified | Medium (5.3) | 0.96% | — | Digitalbazaar Forge | 3/18/2022 | 6/17/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. This can lead to successful verification with signatures that contain invalid… | |
| Modified | High (7.5) | 1.1% | — | Digitalbazaar Forge | 3/18/2022 | 6/17/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not check for tailing garbage bytes after decoding a `DigestInfo` ASN.1 structure. This can allow padding bytes to be removed and garbage data… | |
| Modified | High (7.5) | 0.78% | — | Digitalbazaar Forge | 3/18/2022 | 6/17/2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code is lenient in checking the digest algorithm structure. This can allow a crafted structure that steals padding bytes and uses unchecked portion of… | |
| Modified | Medium (6.1) | 0.84% | — | Digitalbazaar Forge | 1/6/2022 | 6/17/2026 | forge is vulnerable to URL Redirection to Untrusted Site | |
| Modified | High (7.3) | 3.2% | — | Digitalbazaar Forge | 9/1/2020 | 6/17/2026 | The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions. | |
| Modified | High (8.8) | 6.3% | — | Debian LinuxCanonical Ubuntu LinuxCanonical Bazaar | 11/27/2017 | 6/17/2026 | Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117. | |
| Modified | Medium (5.4) | 0.27% | — | ITP Harpers Bazaar ART | 10/21/2014 | 6/17/2026 | The Harpers Bazaar Art (aka com.itp.harpersart) application @7F080181 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modified | High (7.5) | 0.99% | 💥 Exploit | Bazaarbuilder Ecommerce Shopping Cart | 2/2/2009 | 6/16/2026 | SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php. | |
| Modified | High (10) | 3.0% | — | Adempiere Bazaar | 7/30/2007 | 6/16/2026 | Unspecified vulnerability in WebUI in ADempiere Bazaar before 3.3 beta Victoria edition allows remote attackers to access system-level windows via unspecified vectors. |