Vulnerabilities

Summary — last 7 days

New vulnerabilities2,743▼ 518 vs. last week
Critical / high1,293▼ 226 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)244▼ 258 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.6)0.80%—Developer Loggers FOR Simple HistoryAI9/17/20259/25/2026
The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.5 via the enabled_loggers parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary .php files on…
DeferredHigh (7.1)0.37%—Limesquare Lime Developer LoginAI1/22/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in limesquare Lime Developer Login lime-developer-login allows Reflected XSS.This issue affects Lime Developer Login: from n/a through <= 1.4.0.
ModifiedMedium (6.5)0.86%—Developer LOG Project Developer LOG6/16/20156/17/2026
SQL injection vulnerability in the backend module in the Developer Log (devlog) extension before 2.11.4 for TYPO3 allows remote editors to execute arbitrary SQL commands via unspecified vectors.
Orbitaley — Vulnerabilities