Vulnerabilities

Summary — last 7 days

New vulnerabilities3,019▲ 545 vs. last week
Critical / high1,439▲ 265 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)382▲ 175 vs. last week
–

100 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.8)0.55%—Bolt CMSAI8/5/20268/26/2026
Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase. In src/Entity/Field.php, getTwigValue calls shouldBeRenderedAsTwig, which gates rendering only on the field definition's allow_twig flag and a regex checking for , , or…
DeferredMedium (6.5)0.22%—Wbolt Smart SEO ToolAI7/23/20267/23/2026
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
DeferredCritical (9.8)0.64%—Fireboltt FB Bgs001AI7/7/20267/10/2026
Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation. Under specific conditions, previously captured BLE packets can be replayed from a nearby device to trigger…
DeferredLow (2)0.19%—Bolt CMSAI6/8/20267/23/2026
A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a manipulation of the argument style can lead to HTML injection. It is possible to launch the attack remotely. The exploit…
DeferredMedium (6.5)0.40%—Boltcms Bolt CMSAI5/29/20267/21/2026
Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective component. This allows for the extraction of sensitive information
ModifiedHigh (8.4)0.15%—Jwohlwend Boltz2/3/20266/17/2026
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code…
DeferredMedium (4.9)0.16%—Wbolt ImgspiderAI1/22/20266/17/2026
Server-Side Request Forgery (SSRF) vulnerability in wbolt.com IMGspider imgspider allows Server Side Request Forgery.This issue affects IMGspider: from n/a through <= 2.3.12.
AnalyzedMedium (5.5)0.22%—Redboltz Async Mqtt11/24/20256/17/2026
Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via triggering SSL initialization failure that results in incorrect destruction order between io_context and endpoint objects.
DeferredLow (3.8)0.31%—Backupbolt Backup BoltAI10/3/20256/17/2026
The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via the process_backup_batch() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to download directories outside…
DeferredMedium (4.3)0.13%—Backupbolt Backup BoltAI8/27/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Backup Bolt Backup Bolt backup-bolt allows Cross Site Request Forgery.This issue affects Backup Bolt: from n/a through <= 1.5.0.
AnalyzedHigh (7.5)3.6%—Boltcms Bolt7/3/20256/17/2026
Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with valid credentials can inject arbitrary PHP code into the displayname field of the user profile, which is rendered unsanitized in backend templates. The attacker…
AnalyzedMedium (5.5)0.14%—Dell PRO Smart Dock Sd25 FirmwareDell PRO Thunderbolt 4 Smart Dock Sd25tb4 Firmware6/12/20256/17/2026
Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially exploit this vulnerability, leading to Information disclosure.
AnalyzedLow (2.1)0.18%—Passbolt API3/10/20256/17/2026
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.
DeferredMedium (5.4)0.15%—Intel Thunderbolt ShareAI11/13/20246/17/2026
Improper Access Control in some Thunderbolt(TM) Share software before version 1.0.49.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
DeferredHigh (8.2)0.25%—Fireboltt Artillery Smart Watch Nj-r6e-10.3AI10/8/20246/17/2026
Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS).
AnalyzedHigh (7.3)0.17%—Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+3428/28/20246/17/2026
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
AnalyzedMedium (5.3)0.40%—Boltcms Bolt7/31/20246/17/2026
A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creation Handler. The manipulation of the argument title/textarea leads to cross site scripting. It is possible to launch the attack remotely.…
AnalyzedMedium (5.3)0.39%—Boltcms Bolt7/31/20246/17/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Bolt CMS 3.7.1. It has been rated as problematic. This issue affects some unknown processing of the file /preview/page of the component Entry Preview Handler. The manipulation of the argument body leads to cross site scripting. The attack may be initiated…
ModifiedHigh (8.8)0.94%—Wbolt Imgspider7/4/20246/17/2026
The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 2.3.10. This makes it possible for authenticated attackers, with contributor-level and above permissions, to upload arbitrary files on the…
ModifiedHigh (8.8)0.94%—Wbolt Imgspider7/4/20246/17/2026
The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_img_file' function in all versions up to, and including, 2.3.10. This makes it possible for authenticated attackers, with contributor-level and above permissions, to upload arbitrary files on…
DeferredHigh (7)0.17%—Intel Thunderbolt DriverAI5/16/20246/17/2026
Improper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalyzedMedium (4.3)0.48%—Passbolt API4/26/20246/17/2026
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of…
AnalyzedMedium (6.8)0.64%—Passbolt Browser Extension4/26/20246/17/2026
An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords…
AnalyzedHigh (7.5)0.44%—Fireboltt Dream Firmware4/15/20246/17/2026
An issue in Fireboltt Dream Wristphone BSW202_FB_AAC_v2.0_20240110-20240110-1956 allows attackers to cause a Denial of Service (DoS) via a crafted deauth frame.
AnalyzedMedium (4.7)0.55%—Backupbolt Backup Bolt3/18/20246/17/2026
The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors which could contain sensitive information.