Vulnerabilities

Summary — last 7 days

New vulnerabilities2,697▼ 181 vs. last week
Critical / high1,225▼ 327 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 208 vs. last week
–

7 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisMedium (6.8)0.53%—Search-indexerAI8/19/20269/5/2026
A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the…
AnalyzedMedium (6.2)0.89%—Azure ARC Extension Microsoft.azstackhci.operatorAzure ARC Extension Microsoft.azure.hybridnetworkAzure ARC Extension Microsoft.azurekeyvaultsecretsproviderAzure ARC Extension Microsoft.iotoperations.mq+34/9/20246/17/2026
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
ModifiedHigh (8.1)1.7%—Post Indexer Project Post Indexer9/13/20196/17/2026
The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.
ModifiedHigh (7.2)1.5%—Post Indexer Project Post Indexer9/13/20196/17/2026
The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin.
ModifiedHigh (7.8)2.8%💥 ExploitMyphpindexer MY PHP Indexer2/19/20096/16/2026
Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) d and (2) f parameters.
ModifiedMedium (6.8)5.7%💥 ExploitPhpbb Searchindexer10/20/20066/16/2026
PHP remote file inclusion vulnerability in archive/archive_topic.php in pbpbb archive for search engines (SearchIndexer) (aka phpBBSEI) for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
ModifiedMedium (4.3)1.9%💥 ExploitSitesearch Indexer4/1/20066/16/2026
Cross-site scripting (XSS) vulnerability in searchresults.asp in SiteSearch Indexer 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchField parameter.
Orbitaley — Vulnerabilities