Vulnerabilities
Summary — last 7 days
New vulnerabilities2,739▼ 501 vs. last week
Critical / high1,301▼ 201 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 277 vs. last week
20 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.7) | 0.35% | — | Curiosity WorkspaceAI | 9/16/2026 | 9/23/2026 | An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or… | |
| Deferred | Medium (6.3) | 0.39% | — | AiosmtplibAI | 9/12/2026 | 9/23/2026 | aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope… | |
| Deferred | Medium (5.9) | 0.40% | — | AiosmtplibAI | 8/20/2026 | 9/18/2026 | aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacker-chosen SMTP response lines after the… | |
| Deferred | Medium (6.9) | 0.53% | — | AiosmtplibAI | 8/18/2026 | 9/18/2026 | aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is framed as additional standalone SMTP command lines, allowing an attacker who… | |
| Deferred | Medium (6.8) | 0.16% | — | NXP Mifare ClassicAICasfid Servicios Tecnologicos S.l.u Cashless Payment SystemAI | 7/28/2026 | 7/28/2026 | Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). The cryptographic weakness of the authentication algorithm allows an… | |
| Deferred | Medium (5.9) | 0.22% | — | Devignstudiosltd Covid-19 Coronavirus Update Your CustomersAI | 4/24/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devignstudiosltd COVID-19 (Coronavirus) Update Your Customers covid-19-alert allows Stored XSS.This issue affects COVID-19 (Coronavirus) Update Your Customers: from n/a through <= 1.5.1. | |
| Deferred | Medium (5.4) | 0.23% | — | Aio-libs AiosmtpdAI | 5/18/2024 | 6/17/2026 | aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle attack. Version 1.4.6… | |
| Analyzed | Medium (5.3) | 0.37% | — | Aio-libs Aiosmtpd | 3/12/2024 | 6/17/2026 | aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an attacker may send smuggle/spoof e-mails with… | |
| Modified | Critical (9.8) | 0.65% | — | Curiosity Project Curiosity | 1/8/2023 | 6/17/2026 | A vulnerability classified as critical was found in corincerami curiosity. Affected by this vulnerability is an unknown functionality of the file app/controllers/image_controller.rb. The manipulation of the argument sol leads to sql injection. The patch is named d64fddd74ca72714e73f4efe24259ca05c8190eb. It is… | |
| Modified | High (7.5) | 0.82% | — | Axiositalia Registro Elettronico | 6/9/2022 | 6/17/2026 | A vulnerability, which was classified as problematic, has been found in Axios Italia Axios RE 1.7.0/7.0.0. This issue affects some unknown processing of the component Error Message Handler. The manipulation leads to information disclosure (ASP.NET). The attack may be initiated remotely. | |
| Modified | High (8.8) | 0.55% | — | Axiositalia Registro Elettronico | 6/9/2022 | 6/17/2026 | A vulnerability classified as critical was found in Axios Italia Axios RE 1.7.0/7.0.0. This vulnerability affects unknown code of the file REDefault.aspx of the component Connection Handler. The manipulation of the argument DBIDX leads to privilege escalation. The attack can be initiated remotely. | |
| Modified | Medium (6.5) | 1.2% | — | WireWire-ios-transport | 3/11/2022 | 6/17/2026 | Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed resource identifiers may render the iOS Wire Client completely unusable by causing it to repeatedly crash on launch. These malformed resource identifiers can be generated and sent between Wire… | |
| Modified | Medium (6.1) | 0.88% | — | Axiositalia Registro Elettronico | 2/10/2019 | 6/17/2026 | Axios Italia Axios RE 1.7.0/7.0.0 devices have XSS via the RELogOff.aspx Error_Parameters parameter. In some situations, the XSS would be on the family.axioscloud.it cloud service; however, the vendor also supports "Sissi in Rete (con server)" for offline operation. | |
| Modified | Medium (6.1) | 2.3% | 💥 Exploit | Axiositalia Registro Elettronico | 10/23/2018 | 6/17/2026 | In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc parameter. | |
| Modified | Medium (5.4) | 0.27% | — | Magzter Touriosity Travelmag | 10/21/2014 | 6/17/2026 | The Touriosity Travelmag (aka com.magzter.touriositytravelmag) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modified | High (7.1) | 2.5% | — | Cisco IOS SCisco IOS TCisco IOS XR | 5/22/2008 | 6/16/2026 | Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to cause a denial of service (device restart) via unknown vectors, aka Bug ID (1) CSCsk42419, (2) CSCsk60020, and (3) CSCsh51293. | |
| Modified | High (7.8) | 3.4% | — | Cisco IOS Transmission Control Protocol | 5/22/2007 | 6/16/2026 | Cisco IOS 12.4 and earlier, when using the crypto packages and SSL support is enabled, allows remote attackers to cause a denial of service via a malformed (1) ClientHello, (2) ChangeCipherSpec, or (3) Finished message during an SSL session. | |
| Modified | High (7.8) | 4.5% | — | Cisco IOS Transmission Control Protocol | 1/25/2007 | 6/16/2026 | Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device. | |
| Modified | High (10) | 9.3% | — | Cisco IOS Transmission Control Protocol | 1/25/2007 | 6/16/2026 | Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet. | |
| Modified | High (7.8) | 4.9% | — | Cisco IOS Transmission Control Protocol | 1/25/2007 | 6/16/2026 | Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header. |