Vulnerabilities
Summary — last 7 days
New vulnerabilities2,818▲ 71 vs. last week
Critical / high1,488▲ 300 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)68▼ 447 vs. last week
1,206 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (6.5) | 0.19% | — | HCL Digital ExperienceAI | 10/1/2026 | 10/1/2026 | HCL Digital Experience is affected by improper input sanitation. This can result in HTML injection which could be leveraged in content spoofing from a trusted domain. Apply HCL Digital Experience 9.5 CF238 or later to address this. | |
| Deferred | High (8.8) | 0.35% | — | Trex Digital Trex MESAI | 9/30/2026 | 9/30/2026 | Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass. This issue affects Trex MES: through 2026-09-29. | |
| Deferred | Critical (9.8) | 0.48% | — | Trex Digital Smart Manufacturing Systems Trex MESAI | 9/30/2026 | 9/30/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29. | |
| Deferred | High (7.6) | 0.29% | — | Easydigitaldownloads Easy Digital DownloadsAI | 9/23/2026 | 9/23/2026 | Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. | |
| Deferred | Medium (6.6) | 0.23% | — | Digitaldruid HoteldruidAI | 9/14/2026 | 9/22/2026 | HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function. | |
| Deferred | Medium (4.3) | 0.28% | — | Arma Digital Media INC Website TemplateAI | 9/11/2026 | 9/11/2026 | Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Deferred | Critical (9.8) | 0.48% | — | Digital-infrastructureAI | 9/8/2026 | 9/9/2026 | An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password. | |
| Analyzed | Medium (5.3) | 0.31% | — | Lakedrops Digital Signage Framework | 9/2/2026 | 9/16/2026 | Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1. | |
| Deferred | Critical (9.3) | 1.3% | — | Digitalni A Informacni Agentura Eobcanka IdentifikaceAI | 8/31/2026 | 9/1/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacker to register a custom URL scheme (czeeopauth://) for parameterized application execution. Prior to version 3.6.0, incoming… | |
| Deferred | High (7.5) | 0.42% | — | Digital-peak DP CalendarAI | 8/28/2026 | 9/10/2026 | Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar. | |
| Deferred | Medium (6.9) | 0.37% | — | Digital-peak DP CalendarAI | 8/28/2026 | 8/28/2026 | Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles. | |
| Deferred | Medium (4.3) | 0.28% | — | Stratospheredigital WP Courses LMSAI | 8/25/2026 | 8/26/2026 | The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.29 via the 'resultID' parameter due to missing validation on a user controlled key. This makes it possible… | |
| Deferred | Medium (6.5) | 0.22% | — | 93digital Typing EffectAI | 8/18/2026 | 8/20/2026 | Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions. | |
| Deferred | Low (1.3) | 0.39% | — | Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI | 8/17/2026 | 8/20/2026 | A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level… | |
| Awaiting Analysis | Medium (6.1) | 0.15% | — | Intel ALH Digital Audio Interface DriverAIZephyrproject ZephyrAI | 8/12/2026 | 8/26/2026 | The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a caller-supplied int stream_id with no range validation. The value indexes the fixed-size static const uint8_t alh_handshake_map[64] array and scales a FIFO register address, so an out-of-range stream_id… | |
| Deferred | Critical (9.8) | 0.67% | — | Formidable Digital SignaturesAI | 8/11/2026 | 8/12/2026 | The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled… | |
| Deferred | Medium (5.4) | 0.29% | — | HCL Digital ExperienceAIHCL Digital Experience ComposeAI | 8/5/2026 | 8/28/2026 | The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications using the default login portlet. | |
| Deferred | Critical (9.8) | 0.29% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 8/4/2026 | 8/26/2026 | Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Deferred | High (7.4) | 0.34% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 8/4/2026 | 8/26/2026 | Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Deferred | Critical (9.1) | 0.40% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 8/4/2026 | 8/26/2026 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Deferred | Medium (6.5) | 0.35% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 8/4/2026 | 8/26/2026 | Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Deferred | Medium (5.4) | 0.21% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 8/4/2026 | 8/26/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Deferred | Medium (5.3) | 0.33% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 8/4/2026 | 8/26/2026 | Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Deferred | Medium (6.5) | 0.44% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 8/4/2026 | 8/26/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path Traversal. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | |
| Deferred | Medium (5.4) | 0.23% | — | Bilin Software AND Informatics Consultancy INC Humanist Digital Human ResourcesAI | 8/4/2026 | 8/26/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. |