Vulnerabilities
Summary — last 7 days
New vulnerabilities2,819→ no change vs. last week
Critical / high1,469▲ 239 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)83▼ 429 vs. last week
2,684 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Critical (9.8) | — | — | Fortra Core Privileged Access ManagerAI | 10/1/2026 | 10/1/2026 | Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing. | |
| Deferred | High (8.8) | — | — | Bytecore MCP Connector FOR AI ToolsAI | 10/1/2026 | 10/1/2026 | Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions. | |
| Deferred | High (8.8) | — | — | Bytecore Stack MCP Connector FOR AI ToolsAI | 10/1/2026 | 10/1/2026 | The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's… | |
| Awaiting Analysis | Critical (9.3) | 0.43% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative… | |
| Awaiting Analysis | Medium (6.7) | 0.13% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires backend root access on a cluster node and a pending software patch… | |
| Awaiting Analysis | Medium (5.4) | 0.29% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those controls, including enforcement of signed-out and revoked sessions, were… | |
| Awaiting Analysis | Medium (6.6) | 0.55% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service… | |
| Awaiting Analysis | High (7.2) | 0.49% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator… | |
| Awaiting Analysis | High (7.2) | 0.49% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges. | |
| Awaiting Analysis | High (8.1) | 0.38% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have… | |
| Awaiting Analysis | Critical (9.8) | 0.53% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user,… | |
| Awaiting Analysis | Medium (4.6) | 0.23% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or… | |
| Awaiting Analysis | High (8.1) | 0.48% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker… | |
| Awaiting Analysis | High (8.7) | 0.37% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be… | |
| Awaiting Analysis | High (7.2) | 0.95% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command… | |
| Awaiting Analysis | High (7.2) | 0.47% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an… | |
| Awaiting Analysis | High (7.2) | 1.7% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system… | |
| Awaiting Analysis | High (7.2) | 0.49% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator… | |
| Awaiting Analysis | High (8.7) | 0.37% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and… | |
| Awaiting Analysis | Medium (4.3) | 0.27% | — | Kiteworks CoreAI | 9/30/2026 | 10/1/2026 | Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts… | |
| Awaiting Analysis | Medium (6.3) | 0.64% | — | VaadinAIVaadin CoreAIVaadin Charts FlowAIVaadin ChartsAI+1 | 9/30/2026 | 9/30/2026 | A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the… | |
| Deferred | Medium (5.4) | 0.23% | — | Pixfort CoreAI | 9/30/2026 | 9/30/2026 | Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions. | |
| Awaiting Analysis | High (8.1) | 0.20% | — | JupyterlabAIJupyter NotebookAIJupyterlite CoreAI | 9/29/2026 | 9/30/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled… | |
| Awaiting Analysis | Medium (6.8) | 0.26% | — | JupyterlabAIJupyterlite CoreAI | 9/29/2026 | 9/29/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScript after a valid… | |
| Deferred | Low (2) | 0.22% | — | Netcore Nap930AI | 9/29/2026 | 10/1/2026 | A vulnerability was determined in Netcore NAP930 0.1.241010.141410. This vulnerability affects unknown code of the file /lib/functions/backup_common.sh of the component Backup/Restore. This manipulation of the argument aes_pass causes use of hard-coded cryptographic key . It is possible to initiate the attack… |