Vulnerabilities

Summary — last 7 days

New vulnerabilities2,709▼ 126 vs. last week
Critical / high1,231▼ 312 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)257▲ 221 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedCritical (9.6)1.1%⚠ Active exploitation💥 PoCTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+1675/12/20266/17/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
ModifiedCritical (9.3)1.3%—Python-recipe-database Project Python-recipe-database7/11/20226/17/2026
The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModifiedMedium (4.3)1.3%—Adventia E-data3/29/20056/16/2026
Cross-site scripting (XSS) vulnerability in Adventia E-Data 2.0 allows remote attackers to inject arbitrary web script or HTML via a query keyword.