Vulnerabilities

Summary — last 7 days

New vulnerabilities2,544▼ 345 vs. last week
Critical / high1,339▲ 68 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
–

71 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.1)0.34%—Udecode PlateAI9/16/20269/16/2026
Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an application passes untrusted or cross-user HTML to these APIs, certain HTML…
DeferredHigh (8.2)0.36%—Agenticmail ClaudecodeAIAgenticmail CoreAICodexnotes CodexAIOpenclawAI7/20/20267/23/2026
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version 0.9.43, and @agenticmail/openclaw prior to version 0.5.71, two inbound-mail handlers act on a privileged effect without…
DeferredHigh (8.7)0.43%—Udecode PlateAI7/8/20267/10/2026
Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized provider or sourceUrl metadata in useMediaState and skips parseMediaUrl protocol validation, allowing a crafted Plate document to set a known video provider while keeping url as a javascript: iframe…
DeferredMedium (6.6)0.51%—Decode-uri-componentAI6/30/20266/30/2026
decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and 1400 tokens approximately 33s. An attacker…
DeferredHigh (7.5)0.61%—Webp DecoderAI6/25/20266/26/2026
The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.
DeferredHigh (8.1)0.48%—Perl Sereal DecoderAI5/31/20267/22/2026
Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input. In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-reference whose target byte the decoder re-decodes as a fresh tag. When that target byte matches the SHORT_BINARY pattern (an…
AnalyzedHigh (8.6)0.26%—4mhz Base64 Decoder3/24/20266/17/2026
Base64 Decoder 1.1.2 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input file that overflows a buffer, overwrites the SEH chain with a POP-POP-RET gadget address,…
DeferredMedium (6.3)0.14%—AMD Video Decoder Engine FirmwareAI2/12/20266/17/2026
Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system.
AnalyzedMedium (5.7)0.20%—Sencore Decoder-ccv2 FirmwareSencore Smp100 FirmwareSencore En2sdi-2hd Firmware11/18/20256/17/2026
The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint…
AnalyzedMedium (6.5)0.37%—Nwaples Rardecode10/10/20256/17/2026
github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
DeferredHigh (8.3)0.52%—Udecode Plate-coreAIUdecode PlateAI9/20/20246/17/2026
Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature of Plate is the ability to add custom DOM attributes to any element or leaf using the `attributes` property. These attributes are passed to the node component using…
DeferredHigh (8.1)0.50%—Udecode Plate MediaAI7/15/20246/17/2026
Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlParsers` to the `useMediaState` hook may be vulnerable to XSS if a custom parser allows `javascript:`, `data:` or `vbscript:` URLs to be embedded. Editors that do not use `urlParsers` and consume the…
AnalyzedMedium (5.5)0.20%—Mranderson Base64 Encoder/decoder5/15/20247/29/2026
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack
AnalyzedLow (2.4)0.22%—Mranderson Base64 Encoder/decoder5/15/20247/29/2026
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
AnalyzedMedium (4.8)0.75%—Mranderson Base64 Encoder/decoder5/15/20247/29/2026
The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
DeferredMedium (4.3)0.37%—Hidekazu Ishikawa X-t9AIThemeinwp Default MAGAIOUT THE BOX NamahaAIOUT THE BOX CitylogicAI+114/10/20246/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes…
ModifiedHigh (7.5)0.73%—Bosch Monitor WallBosch Videojet Decoder 7513 FirmwareBosch Videojet Decoder 7523 FirmwareBosch Video Recording Manager+112/18/20236/17/2026
An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation.
ModifiedCritical (9.8)4.2%—Moses-smt Mosesdecoder11/27/20236/17/2026
A vulnerability, which was classified as critical, was found in moses-smt mosesdecoder up to 4.0. This affects an unknown part of the file contrib/iSenWeb/trans_result.php. The manipulation of the argument input1 leads to os command injection. The exploit has been disclosed to the public and may be used. The…
ModifiedMedium (6.1)0.45%—Udecode Plate6/9/20236/17/2026
@udecode/plate-link is the link handler for the udecode/plate rich-text editor plugin system for Slate & React. Affected versions of the link plugin and link UI component do not sanitize URLs to prevent use of the `javascript:` scheme. As a result, links with JavaScript URLs can be inserted into the Plate editor…
ModifiedMedium (5.3)0.57%—Juniper Appid Service SigpackJuniper Jdpi-decoder EngineJuniper Junos4/17/20236/17/2026
—
ModifiedHigh (7.1)0.52%—Nongnu Dmidecode4/13/20236/17/2026
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents…
ModifiedMedium (6.5)0.89%—Decode-uri-component Project Decode-uri-componentElastic Kibana2/8/20236/17/2026
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that crashes the Kibana server process.
ModifiedHigh (7.5)24%—Decode-uri-component Project Decode-uri-component11/28/20226/17/2026
decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
ModifiedMedium (5.9)0.36%—Bosch Video Management SystemBosch Videojet Decoder 7513 Firmware9/30/20226/17/2026
Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 versions 10.23 and 10.30 allows man-in-the-middle attacker to compromise confidential video stream. This is only applicable for UDP encryption when target system contains cameras with platform CPP13 or…
ModifiedMedium (5.3)1.3%—Qdecoder Project Qdecoder6/3/20226/17/2026
qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.