Vulnerabilities

Summary — last 7 days

New vulnerabilities2,729▼ 127 vs. last week
Critical / high1,241▼ 295 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 201 vs. last week
–

1,236 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.5)0.18%—Geliver Akillikargo PazaryeriAI10/7/202610/7/2026
The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key…
AnalyzedHigh (8.7)0.59%⚠ Active exploitationCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway10/4/202610/5/2026
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
DeferredMedium (6.1)0.21%—Wpclever WPC Estimated Delivery DateAI10/3/202610/6/2026
The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
DeferredHigh (8.8)0.38%—GO Live Update UrlsAI9/30/20269/30/2026
Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.
DeferredMedium (6.8)0.18%—Bishopfox SliverAI9/29/20269/30/2026
Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads…
Awaiting AnalysisMedium (5.6)0.09%—Dell Live Optics CollectorAI9/28/20269/28/2026
Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
AnalyzedHigh (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway9/27/20269/29/2026
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
ModifiedHigh (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway9/27/20269/29/2026
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior…
ModifiedHigh (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway9/27/20269/29/2026
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior…
ModifiedHigh (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway9/27/20269/29/2026
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to…
ModifiedHigh (7)0.24%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway9/27/20269/29/2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression…
AnalyzedCritical (9.3)0.36%💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway9/27/20269/29/2026
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before…
AnalyzedCritical (9.5)1.3%⚠ Active exploitation💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway9/27/20269/28/2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
AnalyzedCritical (9.5)1.1%⚠ Active exploitation💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway9/27/20269/29/2026
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute…
DeferredHigh (8.5)0.21%—Live Copy PasteAI9/23/20269/23/2026
Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
DeferredMedium (6.4)0.22%—Live ComposerAI9/22/20269/22/2026
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up to, and including, 2.1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
DeferredMedium (4.3)0.60%—Datalogics Ecommerce DeliveryAI9/19/20269/21/2026
The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
Awaiting AnalysisCritical (9.8)0.48%—Oracle Service Delivery PlatformAI9/15/20269/16/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform.…
Awaiting AnalysisCritical (9.8)0.48%—Oracle Service Delivery PlatformAI9/15/20269/16/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.…
Awaiting AnalysisCritical (9.9)0.42%—Oracle Service Delivery PlatformAI9/15/20269/16/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform.…
Awaiting AnalysisCritical (9.9)0.42%—Oracle Service Delivery PlatformAIOracle Fusion MiddlewareAI9/15/20269/16/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery…
Awaiting AnalysisCritical (9.9)0.42%—Oracle Service Delivery PlatformAIOracle Fusion MiddlewareAI9/15/20269/16/2026
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery…
DeferredMedium (4.1)0.15%—Live-bootAI9/11/20269/22/2026
live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.
DeferredCritical (9.3)0.37%—Avideo LivelinksAIWwbn AvideoAI9/10/20269/10/2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor…
Awaiting AnalysisMedium (6.5)0.44%—Live555 Streaming MediaAI9/9/20269/14/2026
A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server.
Orbitaley — Vulnerabilities