Vulnerabilities

Summary — last 7 days

New vulnerabilities2,965▲ 27 vs. last week
Critical / high1,456▲ 193 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)272▼ 254 vs. last week
–

19 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredLow (2.1)1.2%—Jhen0409 React-native-debuggerAI9/24/20269/25/2026
A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Handler. The manipulation of the argument host results in os command injection. It is possible to launch the attack…
DeferredLow (2.1)0.52%—Debugmcp Mcp-debuggerAI5/25/20267/23/2026
A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulation leads to path traversal. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted…
DeferredHigh (8.8)0.61%—Debugger TroubleshooterAI3/30/20266/17/2026
The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1.3.2. This was due to the plugin accepting the wp_debug_troubleshoot_simulate_user cookie value directly as a user ID without any cryptographic validation or authorization checks.…
DeferredCritical (9.1)0.51%—Slajerek RetrodebuggerAI3/24/20266/17/2026
Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.
DeferredHigh (8.5)0.13%—Httpdebugger PROAI1/15/20266/17/2026
HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables and gain elevated access to the system.
DeferredMedium (6.5)0.20%—Debuggers Studio Marquee Addons FOR ElementorAI10/27/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio Marquee Addons for Elementor marquee-addons-for-elementor allows DOM-Based XSS.This issue affects Marquee Addons for Elementor: from n/a through <= 3.8.2.
DeferredMedium (5.4)0.19%—Immunity DebuggerAI3/17/20256/17/2026
Buffer overflow vulnerability in Immunity Debugger affecting version 1.85, its exploitation could allow a local attacker to execute arbitrary code, due to the lack of proper boundary checking.
DeferredMedium (5.5)0.27%—Immunity INC Immunity DebuggerAI2/13/20256/17/2026
A Stack buffer overflow in the arguments parameter in Immunity Inc. Immunity Debugger v1.85 allows attackers to execute arbitrary code via a crafted input that exceeds the buffer size.
DeferredMedium (6.5)0.23%—Debuggers Studio SaaspricingAI12/31/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio SaasPricing saaspricing allows DOM-Based XSS.This issue affects SaasPricing: from n/a through <= 1.2.4.
ModifiedHigh (8.8)0.26%—Template Debugger Project Template Debugger7/11/20236/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Danny Hearnah - ChubbyNinjaa Template Debugger plugin <= 3.1.2 versions.
ModifiedMedium (5.3)0.27%—Madefornet Http Debugger7/5/20236/17/2026
In MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it is possible for an unprivileged application to obtain a handle to the NetFilterSDK wrapper before the service obtains exclusive access.
ModifiedMedium (5.5)0.19%—Edb-debugger Project Edb-debugger4/4/20236/17/2026
An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.
AnalyzedCritical (9)100%⚠ Active exploitationApache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+5112/14/20216/17/2026
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,…
ModifiedCritical (9.1)1.3%—Chameleon Mini Live Debugger Project Chameleon Mini Live Debugger8/28/20206/17/2026
Version 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending all users upgrade to v1.1.8 as soon as possible. For more information, review the referenced GitHub Security Advisory.
ModifiedCritical (9.6)4.6%—Debian LinuxOpenocd Open On-chip Debugger1/16/20186/17/2026
Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.
ModifiedMedium (5)1.4%—Asial Monaca Debugger11/16/20126/16/2026
The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account or (2) session ID information in a system log file via a crafted application.
ModifiedMedium (6.9)0.39%—Debian Mono-debugger10/20/20106/16/2026
The (1) mdb and (2) mdb-symbolreader scripts in mono-debugger 2.4.3, and other versions before 2.8.1, place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
ModifiedHigh (7.2)0.58%—GNU Data Display Debugger12/31/20026/16/2026
Buffer overflow in the GNU DataDisplay Debugger (DDD) 3.3.1 allows local users to execute arbitrary code and possibly gain privileges via a long HOME environment variable. NOTE: since DDD is not installed setuid or setgid, perhaps this issue should not be included in CVE.
ModifiedHigh (7.2)0.36%—SGI Workshop Debugger AND Performance Tools6/20/20006/16/2026
Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files.