Vulnerabilities

Summary — last 7 days

New vulnerabilities2,865▼ 160 vs. last week
Critical / high1,384▲ 52 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)266▼ 260 vs. last week
–

10 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredLow (2.3)0.09%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI5/20/20269/25/2026
Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the report to the transmitted address instead of the address configured on the…
RejectedUnscored——Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI5/20/20269/25/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
DeferredHigh (7.9)0.28%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI5/20/202610/1/2026
Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permission holder is not a vulnerability. Unauthorised access to the functions is addressed under CVE-2026-0856. Improper Control…
DeferredMedium (4.4)0.10%—Mesalvo Meona Client LauncherAIMesalvo Meona ServerAI5/20/20269/25/2026
Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10. MEONA versions before 2024.10 protected stored passwords with SHA-1 (versions from October 2015) or stored them without…
DeferredHigh (7.8)0.13%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI5/20/20269/25/2026
Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verify the role asserted by the MEONA Client. A user who holds a valid MEONA user…
DeferredHigh (8.1)0.52%—Mikado-themes EonaAI3/5/20266/17/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Eona eona allows PHP Local File Inclusion.This issue affects Eona: from n/a through <= 1.3.
DeferredMedium (6.4)0.29%—WP GeonamesAI12/12/20246/17/2026
The WP GeoNames plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-geonames' shortcode in all versions up to, and including, 1.9.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
DeferredHigh (7.1)0.29%—Jacques Malgrange WP GeonamesAI12/6/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacques Malgrange WP GeoNames wp-geonames allows Reflected XSS.This issue affects WP GeoNames: from n/a through <= 1.8.
ModifiedMedium (6.3)0.32%—David Leonard Pkstat5/5/20146/16/2026
tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.
ModifiedHigh (7.5)3.6%—Seth Leonard Book OF GuestsSeth Leonard Post IT12/6/20016/16/2026
Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.