Vulnerabilities
Summary — last 7 days
New vulnerabilities2,748▲ 37 vs. last week
Critical / high1,479▲ 369 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.3) | 0.33% | — | Meshtastic MallaAI | 8/21/2026 | 9/9/2026 | Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered into the DOM without escaping. Any participant on a public Meshtastic MQTT broker can… | |
| Deferred | Medium (5.3) | 0.36% | — | Prasidhdamalla Honeypot FOR WP CommentAI | 4/17/2024 | 6/17/2026 | Missing Authorization vulnerability in Prasidhda Malla Honeypot for WP Comment.This issue affects Honeypot for WP Comment: from n/a through 2.2.3. | |
| Modified | Medium (6.1) | 0.33% | — | Prasidhdamalla Honeypot FOR WP Comment | 2/12/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prasidhda Malla Honeypot for WP Comment allows Reflected XSS.This issue affects Honeypot for WP Comment: from n/a through 2.2.3. |