Vulnerabilities

Summary — last 7 days

New vulnerabilities2,759▼ 357 vs. last week
Critical / high1,278▼ 254 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
–

11 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredLow (1.9)0.16%—Adenot Mcp-google-searchAI8/9/20268/12/2026
A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a manipulation of the argument url can lead to server-side request forgery. The attack is restricted to local execution. This patch is called…
DeferredCritical (9.2)1.4%💥 ExploitCircl Cve-searchAI7/5/20267/6/2026
An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application MongoDB collections. This can expose…
ModifiedMedium (4.3)0.35%—Jenkins Lucene-search4/12/20236/17/2026
Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowing attackers to reindex the database.
ModifiedMedium (6.1)0.69%—Jenkins Lucene-search7/27/20226/17/2026
Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resulting in a reflected cross-site scripting (XSS) vulnerability.
ModifiedMedium (5.4)0.50%—Jenkins Lucene-search7/27/20226/17/2026
Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to reindex the database and to obtain information about jobs otherwise inaccessible to them.
ModifiedMedium (6.1)0.97%—Whoogle-search Project Whoogle-search7/12/20226/17/2026
The package whoogle-search before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via the query string parameter q. In the case where it does not contain the http string, it is used to build the error_message that is then rendered in the error.html template, using the…
ModifiedHigh (7.5)1.9%—Circl Cve-search12/23/20216/17/2026
lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.
ModifiedMedium (6.1)4.7%💥 ExploitE-search Project Esearch10/10/20166/17/2026
Reflected XSS in wordpress plugin e-search v1.0
ModifiedMedium (6.1)2.9%💥 ExploitE-search Project E-search10/10/20166/17/2026
Reflected XSS in wordpress plugin e-search v1.0
ModifiedMedium (4.3)3.5%💥 ExploitWobeo Wp-safe-search12/9/20106/16/2026
Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the v1 parameter.
ModifiedMedium (4.3)1.2%—Wandsoft E-search12/23/20056/16/2026
Cross-site scripting (XSS) vulnerability in WANDSOFT e-SEARCH allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keywords parameter.
Orbitaley — Vulnerabilities