Vulnerabilities

Summary — last 7 days

New vulnerabilities2,773▼ 299 vs. last week
Critical / high1,298▼ 196 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)207▼ 114 vs. last week
–

2 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (6.5)1.2%—Apache HOP Engine3/19/20246/17/2026
Improper Input Validation vulnerability in Apache Hop Engine.This issue affects Apache Hop Engine: before 2.8.0. Users are recommended to upgrade to version 2.8.0, which fixes the issue. When Hop Server writes links to the PrepareExecutionPipelineServlet page one of the parameters provided to the user was not properly…
ModifiedMedium (4.3)0.99%—Ham3d Shop Engine6/18/20146/17/2026
Cross-site scripting (XSS) vulnerability in rating/rating.php in HAM3D Shop Engine allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
Orbitaley — Vulnerabilities