Vulnerabilities
Summary — last 7 days
New vulnerabilities2,856▼ 216 vs. last week
Critical / high1,332▼ 166 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (4.3) | 43% | — | Jenkins Selenium Html Report | 6/30/2021 | 6/17/2026 | Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modified | High (8.8) | 0.75% | — | Polarisoffice Polaris ML Report | 12/16/2020 | 6/17/2026 | An issue was discovered in ML Report Program. There is a stack-based buffer overflow in function sub_41EAF0 at MLReportDeamon.exe. The function will call vsprintf without checking the length of strings in parameters given by attacker. And it finally leads to a stack-based buffer overflow via access to crafted web… | |
| Modified | Critical (9.8) | 2.3% | — | Infraware-global ML Report | 12/28/2018 | 6/17/2026 | ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for code execution. |