Vulnerabilities

Summary — last 7 days

New vulnerabilities2,697▼ 181 vs. last week
Critical / high1,225▼ 327 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 208 vs. last week
–

13 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.8)0.16%—Samsung SemclipboardserviceAI7/10/20267/14/2026
Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.
DeferredHigh (8.5)0.22%—Clevo Hotkey ClipboardAI1/13/20266/17/2026
Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows local non-privileged users to potentially execute code with system privileges. Attackers can exploit the misconfigured service path to inject and execute arbitrary code by placing malicious executables…
DeferredLow (2.3)0.42%—Ckeditor5AICkeditor5-clipboardAI9/4/20256/17/2026
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 44.2.0 through 45.2.1 contain a Cross-Site Scripting (XSS) vulnerability. Ability to exploit could be triggered by a specific user action (leading to unauthorized JavaScript…
DeferredMedium (5.5)0.17%—Samsung ClipboardserviceAI4/8/20256/17/2026
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access files with system privilege. User interaction is required for triggering this vulnerability.
ModifiedMedium (5.4)0.24%—Maheshwaghmare Copy Anything TO Clipboard11/18/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clipboard Agency Copy Anything to Clipboard copy-the-code allows Stored XSS.This issue affects Copy Anything to Clipboard: from n/a through <= 4.0.3.
ModifiedMedium (5.4)0.30%—Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard6/13/20246/17/2026
The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link attribute within the vc_single_image shortcode in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModifiedMedium (5.4)0.51%—Maheshwaghmare Copy Anything TO Clipboard10/20/20236/17/2026
The Copy Anything to Clipboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'copy' shortcode in versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level…
ModifiedMedium (6.5)0.94%—Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard5/6/20216/17/2026
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).
ModifiedMedium (5.4)0.70%—Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard5/6/20216/17/2026
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.
ModifiedMedium (5.5)0.40%—Clipboard Project Clipboard1/8/20186/17/2026
clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.
ModifiedMedium (4.3)2.8%—Redhat OpenshiftZeroclipboard Project Zeroclipboard2/8/20146/17/2026
Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF query parameters (aka loaderInfo.parameters).
ModifiedMedium (4.3)7.3%—Zeroclipboard Project Zeroclipboard4/2/20136/16/2026
Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the same…
ModifiedMedium (4.3)4.5%💥 ExploitZeroclipboard Project Zeroclipboard4/2/20136/16/2026
Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via "the clipText returned from the flash object," a different vulnerability than CVE-2013-1808.
Orbitaley — Vulnerabilities