Vulnerabilities
Summary — last 7 days
New vulnerabilities3,075▲ 488 vs. last week
Critical / high1,457▲ 57 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
25 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.8) | 0.50% | — | ChamawpAI | 8/3/2026 | 8/26/2026 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover. | |
| Deferred | High (8.1) | 0.65% | — | ChamawpAI | 8/3/2026 | 9/29/2026 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code. | |
| Analyzed | High (7.5) | 0.69% | — | Shamaton Msgpack | 3/26/2026 | 10/7/2026 | The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack. | |
| Analyzed | Medium (6.9) | 0.46% | — | Hamastar Meetinghub Paperless Meetings | 1/22/2026 | 6/17/2026 | MeetingHub developed by HAMASTAR Technology has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific API functions and obtain meeting-related information. | |
| Analyzed | Critical (9.3) | 0.76% | — | Hamastar Meetinghub Paperless Meetings | 1/22/2026 | 6/17/2026 | MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analyzed | High (8.7) | 0.67% | — | Hamastar Meetinghub Paperless Meetings | 1/22/2026 | 6/17/2026 | MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files. | |
| Deferred | Critical (9.3) | 0.53% | — | Hamastar Technology WimpAI | 6/16/2025 | 6/17/2026 | The WIMP website co-construction management platform from HAMASTAR Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analyzed | Critical (9.3) | 0.48% | — | Hamastar Meetinghub Paperless Meetings | 8/5/2024 | 6/17/2026 | A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file. | |
| Analyzed | Critical (9.3) | 0.52% | — | Hamastar Meetinghub Paperless Meetings | 8/5/2024 | 6/17/2026 | A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file. | |
| Modified | High (7.5) | 1.3% | — | Apache Hama | 11/21/2022 | 6/17/2026 | missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed. | |
| Modified | High (7.8) | 0.40% | — | Shaman Project Shaman | 2/12/2020 | 6/16/2026 | Shaman 1.0.9: Users can add the line askforpwd=false to his shaman.conf file, without entering the root password in shaman. The next time shaman is run, root privileges are granted despite the fact that the user never entered the root password. | |
| Modified | High (7.5) | 2.2% | — | Chama Memocgi | 7/26/2018 | 6/17/2026 | Directory traversal vulnerability in ChamaNet MemoCGI v2.1800 to v2.2200 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modified | Critical (9.8) | 1.2% | — | Asanhamayesh CMS | 2/26/2018 | 6/17/2026 | SQL injection vulnerability in files.php in the "files" component in ASANHAMAYESH CMS 3.4.6 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter. | |
| Modified | Critical (9.8) | 1.4% | — | Hamayeshnegar CMS | 2/22/2018 | 6/17/2026 | SQL injection vulnerability in users/signup.php in the "signup" component in HamayeshNegar CMS allows a remote attacker to execute arbitrary SQL commands via the "utype" parameter. | |
| Modified | Medium (4.3) | 1.1% | — | Chamanet Chamacargo | 9/16/2013 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in ChamaNet ChamaCargo 7.0000 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modified | Medium (4.6) | 2.1% | — | GitoliteSitaram Chamarty Gitolite | 10/22/2012 | 6/16/2026 | Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name. | |
| Modified | Medium (6) | 0.95% | — | Nurul Hidayah Hamazulan MymesyuaratOscc Mymeeting | 9/11/2012 | 6/16/2026 | Open Source Competency Center (OSCC) MyMeeting 3.0.1 and earlier, and MyMesyuarat 09b-1, does not properly verify uploaded documents, which allows remote authenticated users to execute arbitrary PHP code via a crafted document. | |
| Modified | Medium (6.8) | 0.91% | 💥 Exploit | Webchamado | 6/30/2008 | 6/16/2026 | SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter. | |
| Modified | Medium (6.8) | 0.91% | 💥 Exploit | Webchamado | 6/30/2008 | 6/16/2026 | SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the eml parameter. | |
| Modified | Medium (6.8) | 0.82% | 💥 Exploit | Webchamado | 6/25/2008 | 6/16/2026 | SQL injection vulnerability in index.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the eml parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modified | Medium (6.8) | 1.4% | — | Chama Cargo | 12/4/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in Chama Cargo 4.36 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modified | Low (2.1) | 0.34% | — | Alphamail | 9/14/2006 | 6/16/2026 | AlphaMail before 1.0.16 allows local users to obtain sensitive information via the logging functionality, which displays unencrypted passwords in an error message. NOTE: some details are obtained from third party information. | |
| Modified | Medium (4.3) | 1.4% | — | Ilohamail | 5/2/2005 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IlohaMail 0.8.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the e-mail (1) body, (2) filename, or (3) MIME type. | |
| Modified | High (10) | 1.7% | — | Ilohamail | 12/31/2004 | 6/16/2026 | Unknown vulnerability in IlohaMail before 0.8.14-rc1 has unknown impact and attack vectors. | |
| Modified | High (7.5) | 1.8% | — | Joshua Chamas Apache ASP | 7/11/2000 | 6/16/2026 | The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files. |