Vulnerabilities
Summary — last 7 days
New vulnerabilities2,624▼ 224 vs. last week
Critical / high1,373▲ 143 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)81▼ 449 vs. last week
467 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | High (8.8) | — | — | Microsoft Exchange ServerAI | 10/2/2026 | 10/3/2026 | Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. | |
| Undergoing Analysis | Medium (6) | 0.30% | — | Rabbitmq JMS Topic ExchangeAI | 9/25/2026 | 9/29/2026 | RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, 4.1.14, 4.2.9, and 4.3.3, the optional rabbitmq_jms_topic_exchange plugin's x-jms-topic exchange accepted a client-controlled rjms_erlang_selector binding expression whose LIKE evaluator expanded percent and underscore wildcards into overlapping… | |
| Undergoing Analysis | Medium (6) | 0.29% | — | RabbitmqAIRabbitmq JMS Topic ExchangeAI | 9/23/2026 | 9/24/2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, 4.3.0, When a binding is created on an x-jms-topic exchange, add_binding/3 reads the rjms_erlang_selector argument and passes it through erl_scan:string/1 then erl_parse:parse_term/1. erl_scan:string/1 interns every atom… | |
| Undergoing Analysis | Medium (6) | 0.26% | — | RabbitmqAIRabbitmq Consistent Hash ExchangeAI | 9/23/2026 | 9/24/2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_binding/3 parses the routing key as an integer weight N and computes ring positions with lists:seq(NextN0, NextN0 + N - 1). validate_binding/2 only checks N >= 1 , no upper bound. The resulting list is stored… | |
| Deferred | High (7.5) | 0.35% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 9/10/2026 | 9/10/2026 | Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. | |
| Awaiting Analysis | High (8.1) | 0.72% | — | Microsoft Exchange ServerAI | 9/8/2026 | 9/9/2026 | Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | |
| Analyzed | Critical (9.1) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/22/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analyzed | Medium (5.9) | 0.47% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/29/2026 | Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | |
| Analyzed | High (8.1) | 0.69% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/29/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analyzed | High (7.5) | 1.2% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/29/2026 | Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network. | |
| Analyzed | Medium (6.5) | 0.64% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/29/2026 | Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | |
| Analyzed | Medium (6.5) | 0.84% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/29/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Analyzed | Critical (9.3) | 0.76% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/30/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analyzed | High (8.8) | 0.91% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/8/2026 | 9/30/2026 | External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Deferred | Medium (6.5) | 0.27% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 8/26/2026 | 8/26/2026 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return… | |
| Analyzed | Critical (10) | 0.90% | — | Microsoft Exchange Online | 8/20/2026 | 8/24/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | |
| Awaiting Analysis | Low (3.3) | 0.17% | — | Onnx Open Neural Network ExchangeAI | 8/18/2026 | 9/18/2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a Gemm node has input tensors with fewer… | |
| Analyzed | High (8.8) | 0.94% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/11/2026 | 8/17/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analyzed | Medium (6.5) | 0.64% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/11/2026 | 8/14/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | |
| Analyzed | Medium (5.4) | 0.45% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/11/2026 | 8/13/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Analyzed | High (8.8) | 0.91% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/11/2026 | 8/14/2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Analyzed | Medium (6.5) | 2.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/11/2026 | 8/13/2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. | |
| Modified | High (8) | 0.69% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/11/2026 | 9/2/2026 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analyzed | High (8.8) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/11/2026 | 8/14/2026 | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analyzed | Critical (10) | 0.90% | — | Microsoft Exchange Online | 7/24/2026 | 7/29/2026 | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. |