Vulnerabilities

Summary — last 7 days

New vulnerabilities2,739▼ 510 vs. last week
Critical / high1,303▼ 212 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
–

168 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.3)0.30%—Paidmembershipsincorporated Paid Memberships SubscriptionsAI9/17/20269/18/2026
The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount.
DeferredHigh (7.1)0.27%—Oracle Banking Corporate Lending Process ManagementAI9/15/20269/17/2026
Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…
DeferredHigh (8)0.20%—Oracle Banking Corporate LendingAI9/15/20269/17/2026
Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the…
DeferredHigh (8.8)0.24%—Memberpress Corporate AccountsAI9/12/20269/14/2026
The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like…
DeferredCritical (9.3)0.65%—Sunnet Corporate Training Management SystemAI7/24/20267/28/2026
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a…
DeferredMedium (4.3)0.28%—Gobito Informatics Technologies Corporate Training Management SystemAI7/20/20267/21/2026
Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Training Management System: before dd1a9df64.
DeferredHigh (8.1)0.47%—Pearl Corporate BusinessAI7/2/20267/2/2026
Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
DeferredHigh (8.5)0.14%—PDF Complete Corporate EditionAI1/23/20266/17/2026
PDF Complete Corporate Edition 4.1.45 contains an unquoted service path vulnerability in the pdfcDispatcher service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service binary location to inject malicious executables that will be run with elevated…
DeferredHigh (7.3)0.25%—Divvydrive Information Technologies INC Digital Corporate WarehouseAI11/12/20256/17/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive Information Technologies Inc. Digital Corporate Warehouse allows Stored XSS. This issue affects Digital Corporate Warehouse: before v.4.8.2.22.
DeferredMedium (5.3)0.29%—Vimesoft Information Technologies AND Software Vimesoft Corporate Messaging PlatformAI9/26/20256/17/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. Vimesoft Corporate Messaging Platform allows Retrieve Embedded Sensitive Data. This issue affects Vimesoft Corporate Messaging Platform: from V1.3.0 before V2.0.0.
DeferredMedium (4.3)0.24%—Priyanshumittal SHK CorporateAI9/5/20256/17/2026
Missing Authorization vulnerability in priyanshumittal Shk Corporate shk-corporate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shk Corporate: from n/a through <= 2.4.1.1.
AnalyzedMedium (6.4)0.21%—Corporatezen Responsive Food AND Drink Menu6/26/20256/17/2026
The Responsive Food and Drink Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_pdf_menus shortcode in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
DeferredHigh (8.1)1.0%—Stylemixthemes Pearl Corporate BusinessAI3/26/20256/17/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Pearl - Corporate Business pearl allows PHP Local File Inclusion.This issue affects Pearl - Corporate Business: from n/a through < 3.4.8.
DeferredCritical (9.4)0.76%—Corporate Training Management SystemAI12/19/20246/17/2026
A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a crafted ZIP file.
DeferredHigh (8.6)0.63%—Corporatezen222 Contact Page With Google MAPAI11/20/20246/17/2026
Path Traversal: '.../...//' vulnerability in corporatezen222 Contact Page With Google Map contact-page-with-google-map allows Path Traversal.This issue affects Contact Page With Google Map: from n/a through <= 1.6.1.
ModifiedCritical (9.8)0.42%—Uni-yaz Flexwater Corporate Water Management7/18/20246/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc. FlexWater Corporate Water Management allows SQL Injection. This issue affects FlexWater Corporate Water Management: before 5.452.0.
DeferredCritical (10)0.42%—Vadi Corporate Information Systems Digikent GISAI5/30/20246/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vadi Corporate Information Systems DIGIKENT GIS allows SQL Injection. This issue affects DIGIKENT GIS: through 2.23.5.
DeferredMedium (6.5)0.36%—Looking Forward Software Incorporated Popup BuilderAI3/27/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Looking Forward Software Incorporated. Popup Builder allows Stored XSS.This issue affects Popup Builder: from n/a through 4.2.6.
ModifiedHigh (7.8)0.35%—Univention Corporate Server10/31/20236/17/2026
The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list allowing attackers with local ssh access to gain higher privileges and perform followup attacks. By default, the configuration of UCS does not…
AnalyzedCritical (9.8)100%⚠ Active exploitation💥 ExploitVmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+244/1/20226/17/2026
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
ModifiedMedium (5.5)3.1%—Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+36/12/20216/17/2026
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
ModifiedMedium (5.5)3.4%—Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+86/12/20216/17/2026
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
ModifiedHigh (8.8)77%💥 ExploitXstreamDebian LinuxFedoraproject FedoraNetapp Snapmanager+135/28/202110/7/2026
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's…
ModifiedMedium (5.9)4.9%—NettyDebian LinuxNetapp Oncommand API ServicesNetapp Oncommand Workflow Automation+143/30/20216/17/2026
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not…
ModifiedMedium (5.5)3.3%—Apache PdfboxFedoraproject FedoraOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process Management+153/19/20216/17/2026
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
Orbitaley — Vulnerabilities