Vulnerabilities
Summary — last 7 days
New vulnerabilities2,759▼ 357 vs. last week
Critical / high1,278▼ 254 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
11 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (1.9) | 0.16% | — | Adenot Mcp-google-searchAI | 8/9/2026 | 8/12/2026 | A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local execution. This patch is called… | |
| Deferred | Critical (9.2) | 1.4% | 💥 Exploit | Circl Cve-searchAI | 7/5/2026 | 7/6/2026 | An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This can expose… | |
| Modified | Medium (4.3) | 0.35% | — | Jenkins Lucene-search | 4/12/2023 | 6/17/2026 | Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowing attackers to reindex the database. | |
| Modified | Medium (6.1) | 0.69% | — | Jenkins Lucene-search | 7/27/2022 | 6/17/2026 | Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resulting in a reflected cross-site scripting (XSS) vulnerability. | |
| Modified | Medium (5.4) | 0.50% | — | Jenkins Lucene-search | 7/27/2022 | 6/17/2026 | Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to reindex the database and to obtain information about jobs otherwise inaccessible to them. | |
| Modified | Medium (6.1) | 0.97% | — | Whoogle-search Project Whoogle-search | 7/12/2022 | 6/17/2026 | The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the… | |
| Modified | High (7.5) | 1.9% | — | Circl Cve-search | 12/23/2021 | 6/17/2026 | lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts. | |
| Modified | Medium (6.1) | 4.7% | 💥 Exploit | E-search Project Esearch | 10/10/2016 | 6/17/2026 | Reflected XSS in wordpress plugin e-search v1.0 | |
| Modified | Medium (6.1) | 2.9% | 💥 Exploit | E-search Project E-search | 10/10/2016 | 6/17/2026 | Reflected XSS in wordpress plugin e-search v1.0 | |
| Modified | Medium (4.3) | 3.5% | 💥 Exploit | Wobeo Wp-safe-search | 12/9/2010 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the v1 parameter. | |
| Modified | Medium (4.3) | 1.2% | — | Wandsoft E-search | 12/23/2005 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in WANDSOFT e-SEARCH allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keywords parameter. |