Vulnerabilities
Summary — last 7 days
New vulnerabilities2,523▼ 417 vs. last week
Critical / high1,297▲ 13 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)60▼ 468 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.1) | 0.25% | — | Emlog-proAI | 9/21/2026 | 9/22/2026 | EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell. | |
| Deferred | Critical (9.1) | 0.26% | — | Emlog PROAI | 8/3/2026 | 9/9/2026 | Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST are… | |
| Modified | Medium (5.4) | 0.43% | — | Emlog PRO Project Emlog PRO | 6/9/2022 | 6/17/2026 | Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management. |