Vulnerabilities

Summary — last 7 days

New vulnerabilities2,523▼ 417 vs. last week
Critical / high1,297▲ 13 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)60▼ 468 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.1)0.25%—Emlog-proAI9/21/20269/22/2026
EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.
DeferredCritical (9.1)0.26%—Emlog PROAI8/3/20269/9/2026
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST are…
ModifiedMedium (5.4)0.43%—Emlog PRO Project Emlog PRO6/9/20226/17/2026
Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management.