Vulnerabilities

Summary — last 7 days

New vulnerabilities2,855▼ 333 vs. last week
Critical / high1,381▼ 36 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)296▼ 213 vs. last week
–

6 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.1)0.24%—Http Requests ManagerAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions.
DeferredMedium (5.4)0.33%—Pear Http Request2AI4/17/20256/17/2026
In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.
ModifiedMedium (6.1)0.70%—Facetwp LOG Http Requests10/28/20226/17/2026
The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers who can trick a site's administrator into performing…
ModifiedMedium (6.5)0.84%—Jenkins Http Request7/27/20226/17/2026
Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
ModifiedHigh (7.4)0.91%—Em-http-request Project Em-http-requestFedoraproject Fedora5/25/20206/17/2026
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
ModifiedMedium (5.9)0.57%—Http Request Project Http Request7/23/20196/17/2026
OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing.
Orbitaley — Vulnerabilities