Vulnerabilities
Summary — last 7 days
New vulnerabilities2,706▼ 533 vs. last week
Critical / high1,274▼ 219 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)254▼ 249 vs. last week
8 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.5) | 0.37% | — | Comelit Multi User GatewayAI | 10/1/2026 | 10/5/2026 | Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a… | |
| Deferred | High (8.8) | 0.25% | — | Comelit Multi User GatewayAI | 10/1/2026 | 10/5/2026 | Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password. | |
| Deferred | Low (2.1) | 0.35% | — | SUI Shang Information Technology Suishang Enterprise-level B2b2c Multi-user Mall SystemAI | 10/27/2025 | 6/17/2026 | A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this issue is some unknown functionality of the file /i/359. The manipulation of the argument keywords leads to cross site scripting. The attack is possible to be carried out… | |
| Deferred | Low (2.1) | 0.35% | — | SUI Shang Information Technology Suishang Enterprise-level B2b2c Multi-user Mall SystemAI | 10/27/2025 | 6/17/2026 | A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Affected by this vulnerability is an unknown functionality of the file /Point/index/activity_state/1/category_id/1001. Executing manipulation of the argument category_id can lead to cross site… | |
| Modified | Medium (5.4) | 0.99% | — | Nendeb Fudousan PluginNendeb Fudousan Plugin PRO Multi-userNendeb Fudousan Plugin PRO Single-user | 6/28/2021 | 6/17/2026 | Cross-site scripting vulnerability in Fudousan plugin ver5.7.0 and earlier, Fudousan Plugin Pro Single-User Type ver5.7.0 and earlier, and Fudousan Plugin Pro Multi-User Type ver5.7.0 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modified | High (8.8) | 0.82% | — | Multi User Project Multi User | 9/25/2020 | 6/17/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL. | |
| Modified | High (10) | 3.8% | 💥 Exploit | Plusphp Short URL Multi-user Script | 5/28/2008 | 6/16/2026 | PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the _pages_dir parameter. | |
| Modified | Medium (6.8) | 4.0% | 💥 Exploit | PHP Multi User Randomizer | 5/13/2007 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject arbitrary web script or HTML via (1) the edit_plugin parameter to configure_plugin.tpl.php, or (2) certain array parameters to web/phpinfo.php, as demonstrated by 1[] or a[]. |