Vulnerabilities
Summary — last 7 days
New vulnerabilities2,743▲ 32 vs. last week
Critical / high1,477▲ 367 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
25 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.1) | 0.23% | — | TMT Machine Industry AND Trade Ltd. CO Talassoft Industrial Management SoftwareAI | 9/1/2026 | 9/1/2026 | Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | |
| Deferred | High (7.1) | 0.12% | — | TMT Machine Industry AND Trade Talassoft Industrial Management SoftwareAI | 9/1/2026 | 9/1/2026 | Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | |
| Deferred | High (7.5) | 0.40% | — | TMT Machine Industry AND Trade LTD CO Talassoft Industrial Management SoftwareAI | 9/1/2026 | 9/1/2026 | Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16. | |
| Deferred | High (8.8) | 0.29% | — | TMT Machine Industry AND Trade Talassoft Industrial Management SoftwareAI | 9/1/2026 | 9/1/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. | |
| Deferred | High (7.1) | 0.25% | — | DO LassoAI | 8/13/2026 | 8/14/2026 | Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions. | |
| Deferred | High (7.5) | 0.41% | — | DO LassoAI | 8/13/2026 | 8/14/2026 | Subscriber Path Traversal in Do Lasso <= 358 versions. | |
| Deferred | High (8.5) | 0.36% | — | Entrouvert LassoAI | 8/13/2026 | 8/14/2026 | Subscriber SQL Injection in Do Lasso <= 358 versions. | |
| Deferred | Medium (6.5) | 0.33% | — | DO LassoAI | 8/13/2026 | 8/14/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions. | |
| Deferred | Medium (5.9) | 0.24% | — | Getlasso Simple UrlsAI | 7/2/2026 | 7/2/2026 | Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions. | |
| Analyzed | Critical (9.8) | 1.1% | — | Entrouvert Lasso | 11/5/2025 | 6/17/2026 | A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a malformed SAML response to trigger this vulnerability. | |
| Analyzed | High (7.5) | 0.59% | — | Entrouvert Lasso | 11/5/2025 | 6/17/2026 | A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of service. An attacker can send a malformed SAML response to trigger this vulnerability. | |
| Analyzed | High (7.5) | 0.57% | — | Entrouvert Lasso | 11/5/2025 | 6/17/2026 | A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability. | |
| Analyzed | High (7.5) | 0.59% | — | Entrouvert Lasso | 11/5/2025 | 6/17/2026 | A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability. | |
| Deferred | Medium (5.4) | 0.54% | — | Getlasso Simple UrlsAI | 12/13/2024 | 6/17/2026 | Missing Authorization vulnerability in Andrew Fiebert Simple URLs simple-urls allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple URLs: from n/a through <= 117. | |
| Modified | Medium (5.4) | 0.45% | — | Getlasso Simple Urls | 11/30/2023 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lasso Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management allows Stored XSS.This issue affects Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management: from n/a through… | |
| Modified | High (8.8) | 0.21% | — | Getlasso Simple Urls | 10/16/2023 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lasso Simple URLs plugin <= 120 versions. | |
| Modified | Medium (6.1) | 0.40% | — | Getlasso Simple Urls | 9/27/2023 | 6/17/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lasso Simple URLs plugin <= 117 versions. | |
| Modified | Medium (6.1) | 1.7% | — | Getlasso Simple Urls | 2/13/2023 | 6/17/2026 | The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modified | High (8.8) | 0.94% | — | Getlasso Simple Urls | 2/13/2023 | 6/17/2026 | The Simple URLs WordPress plugin before 115 does not escape some parameters before using them in various SQL statements used by AJAX actions available by any authenticated users, leading to a SQL injection exploitable by low privilege users such as subscriber. | |
| Modified | High (7.5) | 1.3% | — | Entrouvert LassoDebian LinuxFedoraproject Fedora | 6/4/2021 | 6/17/2026 | Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. | |
| Modified | High (7.5) | 3.5% | — | Fedoraproject FedoraEntrouvert Lasso | 8/11/2017 | 6/17/2026 | The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors. | |
| Modified | Medium (4.3) | 1.3% | — | Entrouvert Lasso | 1/7/2009 | 6/16/2026 | Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. | |
| Modified | Medium (6.4) | 1.3% | — | Omnipilot Software Lasso Professional Server | 8/17/2005 | 6/16/2026 | Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags. | |
| Modified | Medium (5) | 1.9% | — | Blue World Communications Lasso WEB Data Engine | 12/31/2002 | 6/16/2026 | Buffer overflow in Blue World Lasso Web Data Engine 3.6.5 allows remote attackers to cause a denial of service via a long URL. | |
| Modified | Medium (5) | 1.3% | — | Blue World Communications Lasso CGI | 8/19/1997 | 6/16/2026 | Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files. |