Vulnerabilities

Summary — last 7 days

New vulnerabilities2,706▼ 533 vs. last week
Critical / high1,274▼ 219 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)254▼ 249 vs. last week
–

8 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.5)0.37%—Comelit Multi User GatewayAI10/1/202610/5/2026
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a…
DeferredHigh (8.8)0.25%—Comelit Multi User GatewayAI10/1/202610/5/2026
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.
DeferredLow (2.1)0.35%—SUI Shang Information Technology Suishang Enterprise-level B2b2c Multi-user Mall SystemAI10/27/20256/17/2026
A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this issue is some unknown functionality of the file /i/359. The manipulation of the argument keywords leads to cross site scripting. The attack is possible to be carried out…
DeferredLow (2.1)0.35%—SUI Shang Information Technology Suishang Enterprise-level B2b2c Multi-user Mall SystemAI10/27/20256/17/2026
A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this vulnerability is an unknown functionality of the file /Point/index/activity_state/1/category_id/1001. Executing manipulation of the argument category_id can lead to cross site…
ModifiedMedium (5.4)0.99%—Nendeb Fudousan PluginNendeb Fudousan Plugin PRO Multi-userNendeb Fudousan Plugin PRO Single-user6/28/20216/17/2026
Cross-site scripting vulnerability in Fudousan plugin ver5.7.0 and earlier, Fudousan Plugin Pro Single-User Type ver5.7.0 and earlier, and Fudousan Plugin Pro Multi-User Type ver5.7.0 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
ModifiedHigh (8.8)0.82%—Multi User Project Multi User9/25/20206/17/2026
A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL.
ModifiedHigh (10)3.8%💥 ExploitPlusphp Short URL Multi-user Script5/28/20086/16/2026
PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the _pages_dir parameter.
ModifiedMedium (6.8)4.0%💥 ExploitPHP Multi User Randomizer5/13/20076/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject arbitrary web script or HTML via (1) the edit_plugin parameter to configure_plugin.tpl.php, or (2) certain array parameters to web/phpinfo.php, as demonstrated by 1[] or a[].
Orbitaley — Vulnerabilities