Vulnerabilities

Summary — last 7 days

New vulnerabilities3,351▲ 378 vs. last week
Critical / high1,495▲ 137 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
–

16 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.8)0.51%—DictionaryAI9/17/20269/18/2026
The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry.
DeferredHigh (7.1)0.16%—Dictionary Wordpress Plugin DictionaryAI9/17/20269/18/2026
The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
DeferredHigh (8.8)0.36%—Style DictionaryAI6/24/20266/25/2026
Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4.3.0 and prior to version 5.4.4. Impact users have: direct usage of `convertTokenData(tokens, { output: 'object' });`; indirect usage, via using Expand API; and/or indirect usage via SD's…
DeferredHigh (7.1)0.30%—Somonator Terms DictionaryAI10/22/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Somonator Terms Dictionary terms-dictionary allows Reflected XSS.This issue affects Terms Dictionary: from n/a through <= 1.5.1.
DeferredHigh (7.1)0.21%—Michel Xili-dictionaryAI6/27/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-dictionary xili-dictionary allows Reflected XSS.This issue affects xili-dictionary: from n/a through <= 2.12.5.2.
DeferredHigh (7.1)0.31%—Michel Xili-dictionaryAI4/1/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-dictionary xili-dictionary allows Reflected XSS.This issue affects xili-dictionary: from n/a through <= 2.12.5.
ModifiedCritical (9.8)7.5%—Ays-pro Personal Dictionary5/9/20226/17/2026
The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.
ModifiedHigh (7.8)0.40%—163 Netease Youdao Dictionary9/3/20206/17/2026
NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissions. This affects Guangzhou NetEase Youdao Dictionary 8.9.2.0.
ModifiedMedium (6.1)0.81%—German Spelling Dictionary Project German Spelling Dictionary8/13/20186/17/2026
A cross-site scripting (XSS) vulnerability was found in valeuraddons German Spelling Dictionary v1.3 (an Opera Browser add-on). Instead of providing text for a spelling check, remote attackers may inject arbitrary web script or HTML via the ajax query parameter in the URL Address Bar.
ModifiedMedium (5.4)0.27%—Herbs & Flowers Dictionary Project Herbs & Flowers Dictionary10/21/20146/17/2026
The Herbs & Flowers Dictionary (aka com.wHerbsNFlowersDictionary) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModifiedMedium (5.4)0.27%—Intsig Camdictionary10/21/20146/17/2026
The CamDictionary (aka com.intsig.camdict) application 2.3.0.20131118 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModifiedHigh (10)1.4%—Netease Youdao Dictionary3/7/20126/16/2026
Unspecified vulnerability in the Youdao Dictionary (com.youdao.dict) application 1.6.1, 2.0.1(2), and 3.0.0(1) for Android has unknown impact and attack vectors.
ModifiedHigh (7.5)0.96%—Xoops Dictionary1/6/20106/16/2026
SQL injection vulnerability in detail.php in the Dictionary module for XOOPS 2.0.18 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModifiedHigh (10)2.5%—Typo3 Dictionary Extension12/31/20086/16/2026
Unspecified vulnerability in the Dictionary (rtgdictionary) extension 0.1.9 and earlier for TYPO3 allows attackers to execute arbitrary code via unknown vectors.
ModifiedMedium (4.3)1.0%—Itirou Maruta MouseoverdictionaryMozilla Firefox10/14/20076/16/2026
Cross-site scripting (XSS) vulnerability in the sidebar HTML page in the MouseoverDictionary before 0.6.2 extension for Mozilla Firefox allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModifiedMedium (4.3)2.0%—Chemical Dictionary6/13/20066/16/2026
Cross-site scripting (XSS) vulnerability in dictionary.php in Chemical Dictionary allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a browse action.