Vulnerabilities
Summary — last 7 days
New vulnerabilities2,697▼ 181 vs. last week
Critical / high1,225▼ 327 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 208 vs. last week
13 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.8) | 0.16% | — | Samsung SemclipboardserviceAI | 7/10/2026 | 7/14/2026 | Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege. | |
| Deferred | High (8.5) | 0.22% | — | Clevo Hotkey ClipboardAI | 1/13/2026 | 6/17/2026 | Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows local non-privileged users to potentially execute code with system privileges. Attackers can exploit the misconfigured service path to inject and execute arbitrary code by placing malicious executables… | |
| Deferred | Low (2.3) | 0.42% | — | Ckeditor5AICkeditor5-clipboardAI | 9/4/2025 | 6/17/2026 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 44.2.0 through 45.2.1 contain a Cross-Site Scripting (XSS) vulnerability. Ability to exploit could be triggered by a specific user action (leading to unauthorized JavaScript… | |
| Deferred | Medium (5.5) | 0.17% | — | Samsung ClipboardserviceAI | 4/8/2025 | 6/17/2026 | Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access files with system privilege. User interaction is required for triggering this vulnerability. | |
| Modified | Medium (5.4) | 0.24% | — | Maheshwaghmare Copy Anything TO Clipboard | 11/18/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clipboard Agency Copy Anything to Clipboard copy-the-code allows Stored XSS.This issue affects Copy Anything to Clipboard: from n/a through <= 4.0.3. | |
| Modified | Medium (5.4) | 0.30% | — | Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard | 6/13/2024 | 6/17/2026 | The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link attribute within the vc_single_image shortcode in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modified | Medium (5.4) | 0.51% | — | Maheshwaghmare Copy Anything TO Clipboard | 10/20/2023 | 6/17/2026 | The Copy Anything to Clipboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'copy' shortcode in versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modified | Medium (6.5) | 0.94% | — | Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard | 5/6/2021 | 6/17/2026 | An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email). | |
| Modified | Medium (5.4) | 0.70% | — | Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard | 5/6/2021 | 6/17/2026 | An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages. | |
| Modified | Medium (5.5) | 0.40% | — | Clipboard Project Clipboard | 1/8/2018 | 6/17/2026 | clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$. | |
| Modified | Medium (4.3) | 2.8% | — | Redhat OpenshiftZeroclipboard Project Zeroclipboard | 2/8/2014 | 6/17/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF query parameters (aka loaderInfo.parameters). | |
| Modified | Medium (4.3) | 7.3% | — | Zeroclipboard Project Zeroclipboard | 4/2/2013 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the same… | |
| Modified | Medium (4.3) | 4.5% | 💥 Exploit | Zeroclipboard Project Zeroclipboard | 4/2/2013 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via "the clipText returned from the flash object," a different vulnerability than CVE-2013-1808. |