Vulnerabilities

Summary — last 7 days

New vulnerabilities2,739▼ 510 vs. last week
Critical / high1,303▼ 212 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
–

157 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.2)0.37%—Wow-company WP CoderAI10/7/202610/7/2026
The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site.
DeferredHigh (7.5)0.24%—Parla Auto Automotive Trading Limited Company Detawix Mobile WEB PortalAI9/29/20269/30/2026
Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19.
DeferredHigh (8.7)0.32%—Brainzcompany Zenius EMSAI9/11/20269/18/2026
Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109).
DeferredMedium (6.5)0.17%—WOO Transport CompanyAI7/23/20267/23/2026
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
DeferredMedium (6.6)0.52%—Wow-company Counter BOXAI6/17/20266/17/2026
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and above, to…
DeferredCritical (9.8)0.53%—Seafood CompanyAI6/17/202610/6/2026
Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.
DeferredHigh (8.8)0.27%—Wow-company WOW FormsAI6/9/20267/21/2026
Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. Attackers can inject SQL code through the 'mwpformid' parameter in requests to the admin-ajax.php endpoint with the…
DeferredHigh (7.2)1.7%—Profelis Information AND Consulting Trade AND Industry Limited Company SambaboxAI5/4/20266/17/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3.
DeferredCritical (9.8)0.56%—Thamerex Work AND Travel CompanyAI3/25/20266/17/2026
Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2.
DeferredMedium (4.3)0.24%—Company Posts FOR LinkedinAI3/21/20266/17/2026
The Company Posts for LinkedIn plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.0. This is due to a missing capability check on the `linkedin_company_post_reset_handler()` function hooked to `admin_post_reset_linkedin_company_post`. This makes it possible for…
DeferredMedium (4.3)0.20%—SAP Fiori APP Intercompany Balance ReconciliationAI1/27/20266/17/2026
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on confidentiality, integrity and availability are not impacted.
DeferredMedium (6.5)0.19%—Micro.company Form TO ChatAI1/22/20266/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Micro.company Form to Chat App form-to-chat allows Stored XSS.This issue affects Form to Chat App: from n/a through <= 1.2.5.
DeferredHigh (8.1)0.30%—SAP Fiori APP Intercompany Balance ReconciliationAI1/13/20266/17/2026
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has high impact on confidentiality and integrity of the application ,availability is not impacted.
DeferredMedium (6.6)0.22%—SAP Fiori APP Intercompany Balance ReconciliationAI1/13/20266/17/2026
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.
DeferredMedium (5.1)0.18%—SAP Fiori APP Intercompany Balance ReconciliationAI1/13/20266/17/2026
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to send uploaded files to arbitrary emails which could enable effective phishing campaigns. This has low impact on confidentiality, integrity and availability of the application.
DeferredMedium (4.3)0.21%—SAP Fiori APP Intercompany Balance ReconciliationAI1/13/20266/17/2026
Under certain conditions SAP Fiori App Intercompany Balance Reconciliation application allows an attacker to access information which would otherwise be restricted. This has low impact on confidentiality of the application, integrity and availability are not impacted.
DeferredMedium (4.3)0.13%—SAP Fiori APP Intercompany Balance ReconciliationAI1/13/20266/17/2026
Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App Intercompany Balance Reconciliation an attacker could execute state?changing actions using an inappropriate request type, this deviation from expected request semantics may allow an attacker to trigger unintended actions on behalf of an…
DeferredHigh (8.7)0.32%—THE QT Company QTAI12/3/20257/29/2026
Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the…
AnalyzedMedium (5.5)0.39%—Torrahclef Company Website CMS11/23/20256/17/2026
A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
AnalyzedMedium (5.5)0.39%—Torrahclef Company Website CMS11/23/20256/17/2026
A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/reset-password.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
DeferredMedium (6.4)0.18%—WP Company InfoAI11/21/20256/17/2026
The WP Company Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'social-networks' shortcode in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
DeferredCritical (9.8)0.36%—Esbi Information AND Telecommunication Industry AND Trade Limited Company Auto Service SoftwareAI9/18/20256/17/2026
CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI Information and Telecommunication Industry and Trade Limited Company Auto Service Software allows SQL Injection. This issue affects Auto Service Software: before v.2025.10.01.
DeferredMedium (6.9)0.22%—Perl PreparecompanyprofileexportjsonAI8/27/20256/17/2026
In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL injection.
DeferredCritical (9.3)0.40%—Torod Company FOR Information Technology TorodAI7/16/20256/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Torod Company for Information Technology Torod torod allows SQL Injection.This issue affects Torod: from n/a through <= 2.1.
AnalyzedLow (2)0.54%—Oretnom23 Simple Company Website6/29/20256/17/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been…
Orbitaley — Vulnerabilities