Vulnerabilities
Summary — last 7 days
New vulnerabilities2,534▼ 399 vs. last week
Critical / high1,321▲ 41 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)96▼ 431 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | High (8.7) | — | — | Mammoth.jsAI | 10/4/2026 | 10/4/2026 | Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to… | |
| Awaiting Analysis | High (8.4) | 0.36% | — | Mammoth.jsAI | 9/24/2026 | 9/24/2026 | mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and… |