Vulnerabilities
Summary — last 7 days
New vulnerabilities2,693▼ 76 vs. last week
Critical / high1,446▲ 304 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.1) | 0.35% | — | Badchoice HandeskAI | 8/11/2026 | 8/28/2026 | A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to other teams via the TicketsController@update endpoint. The endpoint calls no authorize() method and performs no team-scoped ownership check. An attacker with any agent… | |
| Deferred | High (8.1) | 0.35% | — | Badchoice HandeskAI | 8/11/2026 | 8/28/2026 | A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging to other teams via the LeadsController@update endpoint. The endpoint performs no authorization check, and the Lead model has guarded set to an empty array making all columns… |