Vulnerabilities
Summary — last 7 days
New vulnerabilities2,683▼ 54 vs. last week
Critical / high1,442▲ 305 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
60 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.5) | 0.36% | — | Schedule Post Changes With Publishpress FutureAI | 5/5/2026 | 6/17/2026 | The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper' attribute of the [futureaction] shortcode in all versions up to, and including, 4.10.0. This is due to insufficient input sanitization on the wrapper attribute. The plugin uses… | |
| Analyzed | Critical (9.3) | 0.61% | — | Codefuture Image Hosting Script | 4/12/2026 | 6/17/2026 | CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter. | |
| Deferred | Critical (9.8) | 3.2% | — | Slider FutureAI | 2/19/2026 | 6/17/2026 | The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's… | |
| Analyzed | Critical (10) | 1.3% | — | Waterfutures Epyt-flow | 2/6/2026 | 6/17/2026 | EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is… | |
| Deferred | Medium (5.4) | 0.33% | — | Publishpress FutureAI | 1/9/2026 | 6/17/2026 | The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Deferred | Medium (4.3) | 0.19% | — | Schedule Post Changes With Publishpress FutureAI | 11/21/2025 | 6/17/2026 | The Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the "saveFutureActionData" function in all versions up to, and including, 4.9.1. This makes it… | |
| Deferred | Medium (6.9) | 0.32% | — | Century Systems Futurenet MAAICentury Systems Ip-k SeriesAI | 10/31/2025 | 6/17/2026 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication. | |
| Deferred | High (8.6) | 1.2% | — | Century Systems Futurenet MAAICentury Systems Ip-k SeriesAI | 10/31/2025 | 6/17/2026 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of the product may execute an arbitrary OS command. | |
| Deferred | Medium (5.4) | 0.29% | — | Pythoncharmers Python-futureAI | 8/14/2025 | 6/17/2026 | A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to… | |
| Deferred | Medium (6.2) | 0.32% | — | Futurenet NXRAIFuturenet VXRAIFuturenet WXRAI | 4/3/2025 | 6/17/2026 | UNIX symbolic link (Symlink) following issue exists in FutureNet NXR series, VXR series and WXR series routers. Attaching to the affected product an external storage containing malicious symbolic link files, a logged-in administrative user may obtain and/or destroy internal files. | |
| Deferred | Medium (5.3) | 0.51% | — | Century Systems Futurenet ASAICentury Systems FAAI | 3/3/2025 | 6/17/2026 | Buffer overflow vulnerability exists in FutureNet AS series (Industrial Routers) and FA series (Protocol Conversion Machine) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may reboot the device by sending a specially crafted request. | |
| Deferred | High (7.5) | 0.53% | — | Century Systems Futurenet ASAI | 3/3/2025 | 6/17/2026 | Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthenticated attacker may obtain the device information such as MAC address by sending a specially crafted request. | |
| Analyzed | High (8.3) | 0.97% | — | HP Futuresmart 3HP Futuresmart 4HP Futuresmart 5HP 499m7a Firmware+94 | 2/14/2025 | 6/17/2026 | Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job. | |
| Analyzed | Medium (6.3) | 0.94% | — | HP Futuresmart 3HP Futuresmart 5HP Futuresmart 4 | 2/14/2025 | 6/17/2026 | Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job. | |
| Deferred | Medium (6.5) | 0.32% | — | Guangzhou Polar Future Culture Technology University SearchAI | 1/27/2025 | 6/17/2026 | An issue in Guangzhou Polar Future Culture Technology Co., Ltd University Search iOS 2.27.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Deferred | High (7.1) | 0.21% | — | Brandt-net Display Future PostsAI | 12/16/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in brandt-net Display Future Posts display-future-posts allows Stored XSS.This issue affects Display Future Posts: from n/a through <= 0.2.3. | |
| Deferred | Critical (9.8) | 0.55% | — | Century Systems Futurenet NXRAI | 11/29/2024 | 6/17/2026 | FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The… | |
| Modified | Critical (9.8) | 0.65% | — | Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+18 | 7/17/2024 | 6/17/2026 | FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial-of-service (DoS) condition. | |
| Modified | High (8.8) | 0.62% | — | Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+18 | 7/17/2024 | 6/17/2026 | FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed. | |
| Modified | Critical (9.1) | 0.75% | — | Centurysys Futurenet Nxr-1300 FirmwareCenturysys Futurenet Nxr-155/c FirmwareCenturysys Futurenet Nxr-610x FirmwareCenturysys Futurenet Nxr-g050 Firmware+18 | 7/17/2024 | 6/17/2026 | Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to access telnet service unlimitedly. | |
| Analyzed | Medium (6.5) | 0.34% | — | HP Futuresmart 4HP Futuresmart 3HP Futuresmart 5 | 2/21/2024 | 6/17/2026 | Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, when connections made by the device back to services enabled by some solutions may have been trusted without the appropriate CA certificate in the device's certificate store. | |
| Modified | Medium (6.1) | 0.34% | — | HP Futuresmart 5 | 10/4/2023 | 6/17/2026 | Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to WS-Print request and potential injections of Cross Site Scripting via jQuery-UI. | |
| Modified | High (7.5) | 0.87% | — | HP Futuresmart 5 | 6/13/2023 | 6/17/2026 | Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to information disclosure when IPsec is enabled with FutureSmart version 5.6. | |
| Modified | High (7.5) | 1.9% | — | Pythoncharmers Python-future | 12/23/2022 | 6/17/2026 | An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server. | |
| Modified | Critical (9.8) | 0.94% | — | HP Futuresmart 5 | 12/12/2022 | 6/17/2026 | A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Denial of Service when running HP Workpath solutions on potentially affected products. |