Vulnerabilities
Summary — last 7 days
New vulnerabilities2,782▼ 316 vs. last week
Critical / high1,289▼ 234 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.8) | 0.76% | — | Znfit Home Improvement ERP Management System | 2/21/2023 | 6/17/2026 | SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet. | |
| Modified | Medium (5.4) | 0.27% | — | Home Improvement Project Home Improvement | 10/21/2014 | 6/17/2026 | The Home Improvement (aka com.whomeimprovementapp) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |