Vulnerabilities
Summary — last 7 days
New vulnerabilities2,729▼ 127 vs. last week
Critical / high1,241▼ 295 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 201 vs. last week
1,236 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.5) | 0.18% | — | Geliver Akillikargo PazaryeriAI | 10/7/2026 | 10/7/2026 | The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, into which it writes the site's carrier integration key while processing requests from unauthenticated users, allowing attackers to retrieve the key… | |
| Analyzed | High (8.7) | 0.59% | ⚠ Active exploitation | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/4/2026 | 10/5/2026 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28. | |
| Deferred | Medium (6.1) | 0.21% | — | Wpclever WPC Estimated Delivery DateAI | 10/3/2026 | 10/6/2026 | The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Deferred | High (8.8) | 0.38% | — | GO Live Update UrlsAI | 9/30/2026 | 9/30/2026 | Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. | |
| Deferred | Medium (6.8) | 0.18% | — | Bishopfox SliverAI | 9/29/2026 | 9/30/2026 | Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads… | |
| Awaiting Analysis | Medium (5.6) | 0.09% | — | Dell Live Optics CollectorAI | 9/28/2026 | 9/28/2026 | Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analyzed | High (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 9/27/2026 | 9/29/2026 | Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23. | |
| Modified | High (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 9/27/2026 | 9/29/2026 | Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior… | |
| Modified | High (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 9/27/2026 | 9/29/2026 | Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior… | |
| Modified | High (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 9/27/2026 | 9/29/2026 | Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to… | |
| Modified | High (7) | 0.24% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 9/27/2026 | 9/29/2026 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression… | |
| Analyzed | Critical (9.3) | 0.36% | 💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 9/27/2026 | 9/29/2026 | Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before… | |
| Analyzed | Critical (9.5) | 1.3% | ⚠ Active exploitation💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 9/27/2026 | 9/28/2026 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service | |
| Analyzed | Critical (9.5) | 1.1% | ⚠ Active exploitation💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 9/27/2026 | 9/29/2026 | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute… | |
| Deferred | High (8.5) | 0.21% | — | Live Copy PasteAI | 9/23/2026 | 9/23/2026 | Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions. | |
| Deferred | Medium (6.4) | 0.22% | — | Live ComposerAI | 9/22/2026 | 9/22/2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up to, and including, 2.1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Deferred | Medium (4.3) | 0.60% | — | Datalogics Ecommerce DeliveryAI | 9/19/2026 | 9/21/2026 | The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Awaiting Analysis | Critical (9.8) | 0.48% | — | Oracle Service Delivery PlatformAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform.… | |
| Awaiting Analysis | Critical (9.8) | 0.48% | — | Oracle Service Delivery PlatformAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.… | |
| Awaiting Analysis | Critical (9.9) | 0.42% | — | Oracle Service Delivery PlatformAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform.… | |
| Awaiting Analysis | Critical (9.9) | 0.42% | — | Oracle Service Delivery PlatformAIOracle Fusion MiddlewareAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery… | |
| Awaiting Analysis | Critical (9.9) | 0.42% | — | Oracle Service Delivery PlatformAIOracle Fusion MiddlewareAI | 9/15/2026 | 9/16/2026 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery… | |
| Deferred | Medium (4.1) | 0.15% | — | Live-bootAI | 9/11/2026 | 9/22/2026 | live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing. | |
| Deferred | Critical (9.3) | 0.37% | — | Avideo LivelinksAIWwbn AvideoAI | 9/10/2026 | 9/10/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor… | |
| Awaiting Analysis | Medium (6.5) | 0.44% | — | Live555 Streaming MediaAI | 9/9/2026 | 9/14/2026 | A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server. |