Vulnerabilities
Summary — last 7 days
New vulnerabilities3,351▲ 378 vs. last week
Critical / high1,495▲ 137 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
5 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Critical (9.3) | — | — | Internet2 GrouperAI | 9/30/2026 | 9/30/2026 | In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges. | |
| Analyzed | Medium (4.9) | 0.27% | — | Internet2 Grouper | 9/19/2025 | 6/17/2026 | In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs. | |
| Deferred | Critical (9.1) | 0.44% | — | Internet2 GrouperAIInternet2 Grouper FOR WEB ServicesAI | 6/29/2024 | 6/17/2026 | Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1. | |
| Modified | Medium (6.1) | 1.1% | — | Internet2 Grouper | 12/3/2018 | 6/17/2026 | Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary web script or HTML via the code parameter. | |
| Modified | Medium (5.4) | 0.27% | — | Grouperahal Karim Rahal Essoulami | 10/16/2014 | 6/17/2026 | The Karim Rahal Essoulami (aka com.karim.rahal.essoulami.lcxogeyuizteegxvnq) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |