Vulnerabilities
Summary — last 7 days
New vulnerabilities2,733▼ 589 vs. last week
Critical / high1,313▼ 190 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)294▼ 216 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.8) | 5.0% | 💥 Exploit | Iws-geo-form-fields Project Iws-geo-form-fields | 12/26/2022 | 6/17/2026 | The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection. |