Vulnerabilities
Summary — last 7 days
New vulnerabilities2,851▼ 221 vs. last week
Critical / high1,331▼ 168 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
122 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (5.3) | 0.42% | — | Arubanetworks Analytics AND Location Engine | 9/22/2026 | 9/28/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to a specific API endpoint. Successful exploitation could result in the disclosure… | |
| Analyzed | Medium (5.3) | 0.51% | — | Arubanetworks Analytics AND Location Engine | 9/22/2026 | 9/28/2026 | Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted input or leveraging improper security configurations. Successful exploitation could… | |
| Analyzed | High (7.1) | 0.26% | — | Arubanetworks Analytics AND Location Engine | 9/22/2026 | 9/28/2026 | A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the affected appliance. | |
| Analyzed | High (7.2) | 0.84% | — | Arubanetworks Analytics AND Location Engine | 9/22/2026 | 9/28/2026 | Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. | |
| Analyzed | High (7.2) | 0.55% | — | Arubanetworks Analytics AND Location Engine | 9/22/2026 | 9/28/2026 | A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise. | |
| Analyzed | High (7.3) | 0.41% | — | Arubanetworks Analytics AND Location Engine | 9/22/2026 | 9/28/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful… | |
| Analyzed | High (7.5) | 0.46% | — | Arubanetworks Analytics AND Location Engine | 9/22/2026 | 9/28/2026 | A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly processes incoming socket connections. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input during the connection process. Successful exploitation could… | |
| Analyzed | High (7.5) | 0.54% | — | Arubanetworks Analytics AND Location Engine | 9/22/2026 | 9/28/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted requests to certain internal endpoints. Successful exploitation could… | |
| Analyzed | Critical (9.8) | 0.59% | — | Arubanetworks Analytics AND Location Engine | 9/22/2026 | 9/28/2026 | A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the file system with elevated privileges, potentially resulting in full system… | |
| Analyzed | Critical (9.8) | 0.59% | — | Arubanetworks Analytics AND Location Engine | 9/22/2026 | 9/25/2026 | A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacker could exploit this vulnerability by attempting to log in using these known… | |
| Deferred | High (7.5) | 0.46% | — | Ayecode Location ManagerAI | 9/18/2026 | 9/18/2026 | The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameters in all versions up to, and including, 2.3.38 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Awaiting Analysis | Medium (6.9) | 0.44% | — | Ip2location Country BlockerAI | 9/9/2026 | 9/9/2026 | IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers can set the X-Real-IP header to an allowlisted IP address to bypass page, link,… | |
| Deferred | High (8.7) | 0.46% | — | Avideo User LocationAIWwbn AvideoAI | 9/1/2026 | 9/8/2026 | AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly into SQL queries without escaping or prepared statement binding, allowing unauthenticated attackers… | |
| Deferred | High (8.8) | 0.62% | — | CM MAP LocationsAI | 8/25/2026 | 8/27/2026 | The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited Arbitrary File Upload in all versions up to, and including, 2.1.8 via the uploadMedia function. This is due to insufficient file type validation in the upload handler, which performs incomplete… | |
| Deferred | Medium (6.5) | 0.22% | — | Shapedplugin Location WeatherAI | 7/27/2026 | 7/27/2026 | Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions. | |
| Deferred | Medium (6.5) | 0.30% | — | Fahadmahmood Stock Locations FOR WoocommerceAI | 7/13/2026 | 7/13/2026 | Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Locations for WooCommerce: from n/a through <= 3.1.8. | |
| Analyzed | High (7.4) | 0.34% | — | Handkerchief Location Selector | 7/10/2026 | 8/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0. | |
| Analyzed | Medium (6.5) | 0.28% | — | Dopry Geolocation Field | 7/10/2026 | 8/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0. | |
| Deferred | Critical (9.3) | 0.40% | — | Cargo RD Cargo Shipping Location FOR WoocommerceAI | 6/17/2026 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6. | |
| Deferred | Medium (4.3) | 0.35% | — | Shapedplugin Location WeatherAI | 5/22/2026 | 7/24/2026 | The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `lwp_clean_weather_transients()` functions in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with… | |
| Deferred | Medium (5.1) | 0.19% | — | Ip2location Country BlockerAI | 5/10/2026 | 7/24/2026 | WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings that execute when… | |
| Analyzed | High (8.8) | 0.75% | — | Microsoft Azure Custom Locations Resource Provider | 4/3/2026 | 7/24/2026 | Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network. | |
| Modified | High (8.4) | 0.21% | — | Squareapps MY Location | 3/31/2026 | 7/24/2026 | An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Awaiting Analysis | Medium (5.1) | 0.56% | — | Linkit Location Aware Sensor SystemAI | 3/19/2026 | 7/14/2026 | Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious URL containing… | |
| Deferred | Critical (9.8) | 0.37% | — | Multiloca Woocommerce Multi Locations Inventory ManagementAI | 9/24/2025 | 6/17/2026 | The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'wcmlim_settings_ajax_handler' function in all versions up to, and including, 4.2.8. This makes it… |