Vulnerabilities
Summary — last 7 days
New vulnerabilities2,751▲ 29 vs. last week
Critical / high1,468▲ 334 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)85▼ 441 vs. last week
15 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (8.7) | 0.97% | — | Amazon Cognito User PoolAIAmazon OPS WheelAI | 4/24/2026 | 6/17/2026 | Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to deployment admin privileges and manage Cognito user accounts via a crafted UpdateUserAttributes API call that sets the… | |
| Awaiting Analysis | Critical (9.3) | 0.42% | — | Amazon OPS WheelAIAmazon API GatewayAIAmazon CognitoAI | 4/24/2026 | 6/17/2026 | Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the ability to read, modify, and delete all application data across tenants and manage Cognito user accounts within the deployment's User… | |
| Deferred | Medium (6.4) | 0.37% | — | Cognito FormsAI | 12/12/2024 | 6/17/2026 | The Cognito Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 2.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Deferred | Medium (5.4) | 0.47% | — | Incognito Service Activation CenterAI | 11/13/2024 | 6/17/2026 | A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the lastName parameter. | |
| Modified | Medium (4.8) | 0.53% | — | Miniorange Login With Cognito | 1/2/2023 | 6/17/2026 | The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modified | Medium (5.4) | 0.44% | — | Elementalpath Cognitoys Dino Firmware | 8/8/2019 | 6/17/2026 | Cognitoys Dino devices allow profiles_add.html CSRF. | |
| Modified | Medium (6.1) | 0.83% | — | Elementalpath Cognitoys Dino Firmware | 8/8/2019 | 6/17/2026 | Cognitoys Dino devices allow XSS via the SSID. | |
| Modified | High (7.8) | 0.30% | — | Vectra Cognito | 9/21/2018 | 6/17/2026 | Management Console in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local privilege escalation vulnerability. | |
| Modified | Medium (5.4) | 0.52% | — | Vectra Cognito | 9/21/2018 | 6/17/2026 | Vectra Networks Cognito Brain and Sensor before 4.2 contains a cross-site scripting (XSS) vulnerability in the Web Management Console. | |
| Modified | Medium (5.9) | 0.83% | — | Cognitoys Stemosaur Firmware | 12/11/2017 | 6/17/2026 | Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 use AES-128 with ECB mode to encrypt voice traffic between the device and remote server, allowing a malicious user to map encrypted traffic to a particular AES key index and gaining further access to eavesdrop on privacy-sensitive voice… | |
| Modified | Medium (5.9) | 0.65% | — | Cognitoys Stemosaur Firmware | 12/11/2017 | 6/17/2026 | Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small pool of hardcoded keys, allowing a remote attacker to use a different Dino device to decrypt VoIP traffic between a child's Dino and remote server. | |
| Modified | Medium (5.9) | 0.83% | — | Cognitoys Stemosaur Firmware | 12/11/2017 | 6/17/2026 | Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 do not provide sufficient protections against capture-replay attacks, allowing an attacker on the network to replay VoIP traffic between a Dino device and remote server to any other Dino device. | |
| Modified | Critical (9.8) | 1.4% | — | Cognito Moneyworks | 6/26/2017 | 6/17/2026 | Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file. | |
| Modified | Medium (5.4) | 0.27% | — | Incognito Private Browser Project Incognito Private Browser | 9/18/2014 | 6/17/2026 | The INCOgnito Private Browser (aka com.SL.InCoBrowser) application 1.4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modified | Medium (5) | 1.8% | — | Incognito Software INC Ismtp Gateway | 12/31/2002 | 6/16/2026 | iSMTP 5.0.1 allows remote attackers to cause a denial of service via a long "MAIL FROM" command, possibly triggering a buffer overflow. |