Vulnerabilities
Summary — last 7 days
New vulnerabilities2,761▲ 86 vs. last week
Critical / high1,460▲ 350 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)91▼ 420 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.7) | 3.9% | — | Avtech Cloudsetup.cgiAI | 10/9/2025 | 6/17/2026 | AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can… |