Vulnerabilities

Summary — last 7 days

New vulnerabilities3,075▲ 488 vs. last week
Critical / high1,457▲ 57 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
–

25 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredCritical (9.8)0.50%—ChamawpAI8/3/20268/26/2026
The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
DeferredHigh (8.1)0.65%—ChamawpAI8/3/20269/29/2026
The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code.
AnalyzedHigh (7.5)0.69%—Shamaton Msgpack3/26/202610/7/2026
The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.
AnalyzedMedium (6.9)0.46%—Hamastar Meetinghub Paperless Meetings1/22/20266/17/2026
MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information.
AnalyzedCritical (9.3)0.76%—Hamastar Meetinghub Paperless Meetings1/22/20266/17/2026
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AnalyzedHigh (8.7)0.67%—Hamastar Meetinghub Paperless Meetings1/22/20266/17/2026
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
DeferredCritical (9.3)0.53%—Hamastar Technology WimpAI6/16/20256/17/2026
The WIMP website co-construction management platform from HAMASTAR Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
AnalyzedCritical (9.3)0.48%—Hamastar Meetinghub Paperless Meetings8/5/20246/17/2026
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.
AnalyzedCritical (9.3)0.52%—Hamastar Meetinghub Paperless Meetings8/5/20246/17/2026
A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.
ModifiedHigh (7.5)1.3%—Apache Hama11/21/20226/17/2026
missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed.
ModifiedHigh (7.8)0.40%—Shaman Project Shaman2/12/20206/16/2026
Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never entered the root password.
ModifiedHigh (7.5)2.2%—Chama Memocgi7/26/20186/17/2026
Directory traversal vulnerability in ChamaNet MemoCGI v2.1800 to v2.2200 allows remote attackers to read arbitrary files via unspecified vectors.
ModifiedCritical (9.8)1.2%—Asanhamayesh CMS2/26/20186/17/2026
SQL injection vulnerability in files.php in the "files" component in ASANHAMAYESH CMS 3.4.6 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.
ModifiedCritical (9.8)1.4%—Hamayeshnegar CMS2/22/20186/17/2026
SQL injection vulnerability in users/signup.php in the "signup" component in HamayeshNegar CMS allows a remote attacker to execute arbitrary SQL commands via the "utype" parameter.
ModifiedMedium (4.3)1.1%—Chamanet Chamacargo9/16/20136/16/2026
Cross-site scripting (XSS) vulnerability in ChamaNet ChamaCargo 7.0000 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModifiedMedium (4.6)2.1%—GitoliteSitaram Chamarty Gitolite10/22/20126/16/2026
Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name.
ModifiedMedium (6)0.95%—Nurul Hidayah Hamazulan MymesyuaratOscc Mymeeting9/11/20126/16/2026
Open Source Competency Center (OSCC) MyMeeting 3.0.1 and earlier, and MyMesyuarat 09b-1, does not properly verify uploaded documents, which allows remote authenticated users to execute arbitrary PHP code via a crafted document.
ModifiedMedium (6.8)0.91%💥 ExploitWebchamado6/30/20086/16/2026
SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter.
ModifiedMedium (6.8)0.91%💥 ExploitWebchamado6/30/20086/16/2026
SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the eml parameter.
ModifiedMedium (6.8)0.82%💥 ExploitWebchamado6/25/20086/16/2026
SQL injection vulnerability in index.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the eml parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModifiedMedium (6.8)1.4%—Chama Cargo12/4/20066/16/2026
Cross-site scripting (XSS) vulnerability in Chama Cargo 4.36 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModifiedLow (2.1)0.34%—Alphamail9/14/20066/16/2026
AlphaMail before 1.0.16 allows local users to obtain sensitive information via the logging functionality, which displays unencrypted passwords in an error message. NOTE: some details are obtained from third party information.
ModifiedMedium (4.3)1.4%—Ilohamail5/2/20056/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in IlohaMail 0.8.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the e-mail (1) body, (2) filename, or (3) MIME type.
ModifiedHigh (10)1.7%—Ilohamail12/31/20046/16/2026
Unknown vulnerability in IlohaMail before 0.8.14-rc1 has unknown impact and attack vectors.
ModifiedHigh (7.5)1.8%—Joshua Chamas Apache ASP7/11/20006/16/2026
The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.
Orbitaley — Vulnerabilities