Vulnerabilities
Summary — last 7 days
New vulnerabilities2,571▼ 296 vs. last week
Critical / high1,355▲ 107 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
5,631 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | Low (3.7) | 0.14% | — | Smackcoders WP Ultimate CSV ImporterAI | 10/3/2026 | 10/3/2026 | The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a… | |
| Received | Low (3.5) | 0.15% | — | Smackcoders WP Ultimate CSV ImporterAI | 10/3/2026 | 10/3/2026 | The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite… | |
| Received | High (8.7) | 0.53% | — | Codeart Google MP3 Audio PlayerAI | 10/2/2026 | 10/2/2026 | CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request… | |
| Deferred | Low (2) | 0.28% | — | Bytecodealliance WasmtimeAI | 10/2/2026 | 10/2/2026 | Wasmtime is a runtime for WebAssembly. From 46.0.0 until 46.0.2 and 47.0.3, fuel and epoch preemption checks inside bulk operations including memory.copy, table.grow, and array.copy can expose invalid intermediate state when an embedder mutates a Store in Store::epoch_deadline_callback or continues using a Store after… | |
| Deferred | High (8.1) | 0.39% | — | Taskingai QR Code GeneratorAI | 10/2/2026 | 10/2/2026 | In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter. | |
| Deferred | Low (2.1) | 0.20% | — | Codeastro Simple Loan Management SystemAI | 10/2/2026 | 10/2/2026 | A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument g_name results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used… | |
| Deferred | Low (2.1) | 0.20% | — | Codeastro Simple Pharmacy Management SystemAI | 10/2/2026 | 10/2/2026 | A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might… | |
| Deferred | Low (2.1) | 0.20% | — | Codeastro Simple Pharmacy Management SystemAI | 10/2/2026 | 10/2/2026 | A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may… | |
| Deferred | Low (2.1) | 0.27% | — | Sourcecodester Student Result Management SystemAI | 10/2/2026 | 10/2/2026 | A vulnerability was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file script/academic/core/new_announcement.php of the component Announcement Module. The manipulation of the argument title/announcement results in cross site scripting. It is possible to launch the… | |
| Deferred | Low (2.1) | 0.25% | — | Itsourcecode Online Admission SystemAI | 10/2/2026 | 10/2/2026 | A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The impacted element is an unknown function of the file confirm.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used… | |
| Deferred | Medium (4.3) | 0.15% | — | Code-atlantic Popup MakerAI | 10/2/2026 | 10/2/2026 | The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service… | |
| Deferred | Medium (5.5) | 0.33% | — | Sourcecodester Online Reviewer Management SystemAI | 10/2/2026 | 10/2/2026 | A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=activity. The manipulation of the argument Title results in sql injection. The attack may be… | |
| Deferred | Low (2.1) | 0.20% | — | Itsourcecode PET Shop Management SystemAI | 10/2/2026 | 10/2/2026 | A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be… | |
| Deferred | Low (2.1) | 0.20% | — | Itsourcecode PET Shop Management SystemAI | 10/2/2026 | 10/2/2026 | A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may… | |
| Deferred | Medium (5.1) | 0.16% | — | Codexonics Prime MoverAI | 10/1/2026 | 10/2/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped site_title value in a package's footprint.json file. Attackers can place a crafted package under the prime-mover-export-files directory… | |
| Deferred | High (7) | 0.34% | — | Codexonics Prime MoverAI | 10/1/2026 | 10/2/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted WPRIME/TAR package with manipulated tar_root_folder values in wprime-config.json. Attackers can exploit insufficient path validation… | |
| Deferred | High (8.6) | 0.59% | — | Codexonics Prime MoverAI | 10/1/2026 | 10/2/2026 | The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by… | |
| Deferred | Low (2.1) | 0.33% | — | Itsourcecode Leave Management SystemAI | 10/1/2026 | 10/1/2026 | A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects unknown code of the file /module/leave/controller.php. Executing a manipulation of the argument LEAVEID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. | |
| Deferred | Medium (5.3) | 0.20% | — | Smackcoders WP Ultimate CSV ImporterAI | 10/1/2026 | 10/1/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1. | |
| Deferred | Low (2.1) | 0.20% | — | Itsourcecode Leave Management SystemAI | 10/1/2026 | 10/1/2026 | A vulnerability has been found in itsourcecode Leave Management System 1.0. The affected element is an unknown function of the file /module/leavetype/controller.php. Such manipulation of the argument LEAVTID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Undergoing Analysis | Critical (10) | 0.46% | — | Joomcode JctablesAI | 9/30/2026 | 9/30/2026 | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated… | |
| Deferred | High (7.2) | 0.37% | — | Implecode Ecommerce Product CatalogAI | 9/30/2026 | 9/30/2026 | Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. | |
| Deferred | High (7.5) | 0.30% | — | Codection Import AND Export Users AND CustomersAI | 9/30/2026 | 9/30/2026 | Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions. | |
| Awaiting Analysis | Low (2) | 0.10% | — | Anthropic Claude CodeAI | 9/30/2026 | 9/30/2026 | Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead of the user's valid Claude Enterprise or Team sign-in when fetching the organization's server-managed settings, even though the session itself authenticated with the Enterprise or… | |
| Deferred | High (8.7) | 0.33% | — | Codesys Gateway ClientAI | 9/30/2026 | 9/30/2026 | The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus… |