Vulnerabilities
Summary — last 7 days
New vulnerabilities2,811▲ 64 vs. last week
Critical / high1,484▲ 296 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)68▼ 448 vs. last week
16 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.3) | 0.53% | — | Ebyte Configuration UtilityAI | 8/31/2026 | 9/1/2026 | The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing… | |
| Deferred | High (7.1) | 0.45% | — | Johnsoncontrols Istar Configuration UtilityAI | 1/28/2026 | 6/17/2026 | Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iSTAR Configuration Utility (ICU) version 6.9.7 and prior. Successful exploitation of this vulnerability could result in failure within the operating system of the machine hosting the ICU tool. | |
| Deferred | Medium (5.4) | 0.13% | — | Intel Server Configuration UtilityAIIntel Server Firmware Update UtilityAI | 11/11/2025 | 6/17/2026 | Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware Update Utility software before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user… | |
| Deferred | Medium (6.3) | 0.24% | — | Istar Configuration UtilityAI | 6/11/2025 | 6/17/2026 | The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the Windows PC that ICU is running on. | |
| Deferred | Critical (9.3) | 0.57% | — | Istar Configuration UtilityAI | 4/24/2025 | 6/17/2026 | Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue | |
| Analyzed | Medium (6.7) | 0.19% | — | Intel Qsfp+ Configuration Utility | 2/14/2024 | 6/17/2026 | Uncontrolled search path in Intel(R) QSFP+ Configuration Utility software, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modified | High (7.8) | 0.18% | — | Intel Server Configuration Utility | 11/14/2023 | 6/17/2026 | Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modified | High (7.8) | 0.19% | — | Intel Server Configuration Utility | 11/14/2023 | 6/17/2026 | Unquoted search path in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modified | High (7.8) | 0.38% | — | Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+5 | 7/24/2020 | 6/17/2026 | In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification. | |
| Modified | High (7.8) | 0.22% | — | Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+5 | 7/24/2020 | 6/17/2026 | In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure,… | |
| Modified | High (7.8) | 0.27% | — | Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+5 | 7/24/2020 | 6/17/2026 | In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a… | |
| Modified | Low (3.7) | 1.3% | — | Netgear Prosafe Plus Configuration Utility | 4/28/2017 | 6/17/2026 | ProSAFE Plus Configuration Utility prior to 2.3.29 allows remote attackers to bypass access restriction and change configurations of the switch via SOAP requests. | |
| Modified | Low (2.1) | 0.53% | — | HP Array Configuration UtilityHP Array Diagnostics UtilityHP Proliant Array DiagnosticsHP Smartssd Wear Gauge Utility | 4/12/2014 | 6/17/2026 | Unspecified vulnerability in HP Array Configuration Utility, Array Diagnostics Utility, ProLiant Array Diagnostics, and SmartSSD Wear Gauge Utility 9.40 and earlier allows local users to gain privileges via unknown vectors. | |
| Modified | Medium (4) | 6.4% | — | F5 Big-ip Configuration Utility | 1/21/2014 | 6/16/2026 | XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows remote authenticated users to read arbitrary files via a crafted XML file. | |
| Modified | Medium (5) | 2.6% | — | Intel CLI Auto-configuration UtilityIntel Client System Setup UtilityIntel Server Configuration WizardIntel Server Control+18 | 12/31/2004 | 6/16/2026 | The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled. | |
| Modified | High (7.5) | 1.3% | — | Apple TCP IP Configuration Utility | 12/31/2002 | 6/16/2026 | The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a blank Telnet password, which allows remote attackers to gain access. |