Vulnerabilities

Summary — last 7 days

New vulnerabilities2,566▼ 354 vs. last week
Critical / high1,319▲ 46 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)76▼ 451 vs. last week
–

1,900 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.1)0.17%—Sublinear-time-solverAIConsciousness-explorerAI8/25/20269/9/2026
sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state and import_state tools in src/consciousness-explorer/mcp/server.js pass the attacker-controlled filepath…
DeferredMedium (5.5)0.47%—Modelcontextprotocol MCP RDF ExplorerAI8/13/20268/14/2026
A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the component MCP Server. Performing a manipulation of the argument url results in server-side request forgery. The attack may be initiated remotely. The…
AnalyzedCritical (9.6)0.86%—Microsoft Azure Storage Explorer8/11/20268/17/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
AnalyzedHigh (7.8)0.12%—Synology Hyper Backup Explorer6/3/20267/22/2026
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
Awaiting AnalysisHigh (8.2)0.10%—Graph ExplorerAI6/2/20267/22/2026
Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests intended to be sent over HTTPS. To remediate this issue, users should upgrade to Graph Explorer v3.0.1 or later.
AnalyzedHigh (8.6)0.12%—Draeger Infinity Explorer C700 Firmware6/1/20267/22/2026
Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display…
DeferredLow (2.1)0.28%—Orthanc Explorer 2AI5/31/20267/22/2026
A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the component URL Handler. This manipulation of the argument remote-source causes cross site scripting. It is possible to initiate the attack…
DeferredHigh (8.6)0.16%—10-strike Network Inventory ExplorerAI5/23/20267/23/2026
10-Strike Network Inventory Explorer 8.54 contains a stack-based buffer overflow vulnerability in the registration key input field that allows local attackers to execute arbitrary code by triggering a structured exception handler overwrite. Attackers can craft a malicious registration key string with 4188 bytes of…
DeferredCritical (9.3)0.26%—SketchupAIMicrosoft Internet ExplorerAI5/22/20267/23/2026
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary…
DeferredMedium (6.5)0.48%—Microsoft Kafka Sink Azure KustoAIApache KafkaAIMicrosoft Azure Data ExplorerAI5/11/20266/17/2026
kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the kusto.tables.topics.mapping configuration. The db, table, mapping, and format fields of each mapping entry were…
DeferredLow (2.9)0.40%—Collabora KodexplorerAI4/19/20266/17/2026
A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown functionality of the file /app/controller/share.class.php of the component fileUpload Endpoint. The manipulation of the argument fileUpload leads to improper authorization. Remote exploitation of the…
DeferredLow (2.1)0.36%—Kodcloud KodexplorerAI4/19/20266/17/2026
A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGroupAction of the file /app/controller/systemRole.class.php. Executing a manipulation of the argument group_role can lead to authorization bypass. The attack may be launched remotely. The exploit has…
DeferredLow (2)0.40%—Kodcloud KodexplorerAI4/19/20266/17/2026
A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file /app/controller/systemMember.class.php. Performing a manipulation of the argument path results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the…
DeferredMedium (6.9)0.65%—Kodcloud KodexplorerAI4/19/20266/17/2026
A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/controller/share.class.php of the component fileGet Endpoint. Such manipulation of the argument fileUrl leads to improper authentication. The attack can be launched remotely. The vendor was contacted…
DeferredMedium (5.5)0.72%—Kodcloud KodexplorerAI4/19/20266/17/2026
A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument path causes path traversal. The attack can be initiated remotely. The exploit…
AnalyzedMedium (4.3)0.35%—SAP Hana CockpitSAP Hana Database Explorer4/14/20266/17/2026
Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer
DeferredMedium (6.9)0.15%—Remote Process ExplorerAI4/5/20267/24/2026
Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the added computer,…
AnalyzedHigh (8.1)0.43%—Pab1it0 Azure Data Explorer MCP Server3/27/20266/17/2026
Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP…
AnalyzedHigh (8.6)0.22%—Rttsoftware PDF Explorer3/26/20266/17/2026
PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the Custom fields…
DeferredMedium (6.9)0.13%—Spotie Internet Explorer Password RecoveryAI3/11/20266/17/2026
SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a…
AnalyzedCritical (9.3)0.96%—Xiaomi Fileexplorer3/11/20267/14/2026
MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows…
AnalyzedHigh (7.5)1.0%—Microsoft Azure IOT Explorer3/10/20266/17/2026
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.
AnalyzedHigh (7.5)1.00%—Microsoft Azure IOT Explorer3/10/20266/17/2026
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
AnalyzedHigh (7.5)0.72%—Microsoft Azure IOT Explorer3/10/20266/17/2026
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
AnalyzedHigh (7.5)0.70%—Microsoft Azure IOT Explorer3/10/20266/17/2026
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.