Vulnerabilities
Summary — last 7 days
New vulnerabilities3,351▲ 378 vs. last week
Critical / high1,495▲ 137 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
16 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.8) | 0.51% | — | DictionaryAI | 9/17/2026 | 9/18/2026 | The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry. | |
| Deferred | High (7.1) | 0.16% | — | Dictionary Wordpress Plugin DictionaryAI | 9/17/2026 | 9/18/2026 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request. | |
| Deferred | High (8.8) | 0.36% | — | Style DictionaryAI | 6/24/2026 | 6/25/2026 | Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4.3.0 and prior to version 5.4.4. Impact users have: direct usage of `convertTokenData(tokens, { output: 'object' });`; indirect usage, via using Expand API; and/or indirect usage via SD's… | |
| Deferred | High (7.1) | 0.30% | — | Somonator Terms DictionaryAI | 10/22/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Somonator Terms Dictionary terms-dictionary allows Reflected XSS.This issue affects Terms Dictionary: from n/a through <= 1.5.1. | |
| Deferred | High (7.1) | 0.21% | — | Michel Xili-dictionaryAI | 6/27/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-dictionary xili-dictionary allows Reflected XSS.This issue affects xili-dictionary: from n/a through <= 2.12.5.2. | |
| Deferred | High (7.1) | 0.31% | — | Michel Xili-dictionaryAI | 4/1/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-dictionary xili-dictionary allows Reflected XSS.This issue affects xili-dictionary: from n/a through <= 2.12.5. | |
| Modified | Critical (9.8) | 7.5% | — | Ays-pro Personal Dictionary | 5/9/2022 | 6/17/2026 | The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability. | |
| Modified | High (7.8) | 0.40% | — | 163 Netease Youdao Dictionary | 9/3/2020 | 6/17/2026 | NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissions. This affects Guangzhou NetEase Youdao Dictionary 8.9.2.0. | |
| Modified | Medium (6.1) | 0.81% | — | German Spelling Dictionary Project German Spelling Dictionary | 8/13/2018 | 6/17/2026 | A cross-site scripting (XSS) vulnerability was found in valeuraddons German Spelling Dictionary v1.3 (an Opera Browser add-on). Instead of providing text for a spelling check, remote attackers may inject arbitrary web script or HTML via the ajax query parameter in the URL Address Bar. | |
| Modified | Medium (5.4) | 0.27% | — | Herbs & Flowers Dictionary Project Herbs & Flowers Dictionary | 10/21/2014 | 6/17/2026 | The Herbs & Flowers Dictionary (aka com.wHerbsNFlowersDictionary) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modified | Medium (5.4) | 0.27% | — | Intsig Camdictionary | 10/21/2014 | 6/17/2026 | The CamDictionary (aka com.intsig.camdict) application 2.3.0.20131118 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modified | High (10) | 1.4% | — | Netease Youdao Dictionary | 3/7/2012 | 6/16/2026 | Unspecified vulnerability in the Youdao Dictionary (com.youdao.dict) application 1.6.1, 2.0.1(2), and 3.0.0(1) for Android has unknown impact and attack vectors. | |
| Modified | High (7.5) | 0.96% | — | Xoops Dictionary | 1/6/2010 | 6/16/2026 | SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modified | High (10) | 2.5% | — | Typo3 Dictionary Extension | 12/31/2008 | 6/16/2026 | Unspecified vulnerability in the Dictionary (rtgdictionary) extension 0.1.9 and earlier for TYPO3 allows attackers to execute arbitrary code via unknown vectors. | |
| Modified | Medium (4.3) | 1.0% | — | Itirou Maruta MouseoverdictionaryMozilla Firefox | 10/14/2007 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in the sidebar HTML page in the MouseoverDictionary before 0.6.2 extension for Mozilla Firefox allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modified | Medium (4.3) | 2.0% | — | Chemical Dictionary | 6/13/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in dictionary.php in Chemical Dictionary allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a browse action. |