Vulnerabilities

Summary — last 7 days

New vulnerabilities2,856▼ 216 vs. last week
Critical / high1,332▼ 166 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (4.3)43%—Jenkins Selenium Html Report6/30/20216/17/2026
Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModifiedHigh (8.8)0.75%—Polarisoffice Polaris ML Report12/16/20206/17/2026
An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportDeamon.exe. The function will call vsprintf without checking the length of strings in parameters given by attacker. And it finally leads to a stack-based buffer overflow via access to crafted web…
ModifiedCritical (9.8)2.3%—Infraware-global ML Report12/28/20186/17/2026
ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for code execution.