Vulnerabilities
Summary — last 7 days
New vulnerabilities2,697▼ 181 vs. last week
Critical / high1,225▼ 327 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 208 vs. last week
7 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (6.8) | 0.53% | — | Search-indexerAI | 8/19/2026 | 9/5/2026 | A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the… | |
| Analyzed | Medium (6.2) | 0.89% | — | Azure ARC Extension Microsoft.azstackhci.operatorAzure ARC Extension Microsoft.azure.hybridnetworkAzure ARC Extension Microsoft.azurekeyvaultsecretsproviderAzure ARC Extension Microsoft.iotoperations.mq+3 | 4/9/2024 | 6/17/2026 | Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability | |
| Modified | High (8.1) | 1.7% | — | Post Indexer Project Post Indexer | 9/13/2019 | 6/17/2026 | The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function. | |
| Modified | High (7.2) | 1.5% | — | Post Indexer Project Post Indexer | 9/13/2019 | 6/17/2026 | The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin. | |
| Modified | High (7.8) | 2.8% | 💥 Exploit | Myphpindexer MY PHP Indexer | 2/19/2009 | 6/16/2026 | Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) d and (2) f parameters. | |
| Modified | Medium (6.8) | 5.7% | 💥 Exploit | Phpbb Searchindexer | 10/20/2006 | 6/16/2026 | PHP remote file inclusion vulnerability in archive/archive_topic.php in pbpbb archive for search engines (SearchIndexer) (aka phpBBSEI) for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modified | Medium (4.3) | 1.9% | 💥 Exploit | Sitesearch Indexer | 4/1/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in searchresults.asp in SiteSearch Indexer 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchField parameter. |