Vulnerabilities

Summary — last 7 days

New vulnerabilities2,748▲ 38 vs. last week
Critical / high1,479▲ 369 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
–

1,316 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisMedium (6.3)——Vercel Next.jsAI10/2/202610/2/2026
Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor's Draft Mode…
Awaiting AnalysisMedium (6.3)——Vercel Next.jsAI10/2/202610/2/2026
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request…
Awaiting AnalysisLow (2.3)——Vercel Next.jsAI10/2/202610/2/2026
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk…
Awaiting AnalysisMedium (6.3)——Vercel Next.jsAI10/2/202610/2/2026
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint without reliably restricting cross-site requests. A malicious website visited by a developer can reach the endpoint and read the project's disk…
Awaiting AnalysisMedium (6.3)——Vercel Next.jsAI10/2/202610/2/2026
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration routes can use a shared response cache key that is insufficiently scoped to the source route. A single…
Awaiting AnalysisHigh (8.3)——Vercel Next.jsAI10/2/202610/2/2026
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach private IP addresses after the URL passes the allow-list…
Awaiting AnalysisMedium (6.3)0.32%—Vercel Next.jsAI10/1/202610/2/2026
Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a 'use cache' function that calls another 'use cache' function that reads a root param can be keyed…
DeferredHigh (7.5)0.40%—Nextgen GalleryAI9/30/20269/30/2026
Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.
DeferredMedium (6.4)0.16%—Nextendweb Smart Slider 3AI9/30/20269/30/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
DeferredMedium (6.9)0.50%—Notionnext-org NotionnextAI9/28/20269/28/2026
A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the function cleanCache of the file pages/api/cache.js of the component Authentication Guard. The manipulation of the argument token leads to missing authentication. The attack may be initiated remotely.…
DeferredMedium (5.9)0.19%—Nextscripts Social Networks Auto PosterAI9/27/20269/28/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials,…
DeferredMedium (5.3)0.22%—Frappe ErpnextAI9/23/20269/29/2026
Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python paths to invoke non-whitelisted internal server-side methods and read their return…
Awaiting AnalysisHigh (7.7)0.38%—RTI Connext ProfessionalAI9/22/20269/23/2026
Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects Connext Professional: from 7.6.0 before 7.7.0.1.
Awaiting AnalysisCritical (10)0.31%—RTI Connext ProfessionalAI9/22/20269/23/2026
Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.3x…
Awaiting AnalysisMedium (6.8)0.10%—RTI Connext ProfessionalAI9/22/20269/22/2026
Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 5.0.0 before…
Awaiting AnalysisHigh (7.3)0.08%—RTI Connext ProfessionalAI9/22/20269/22/2026
Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*.
Awaiting AnalysisCritical (9.2)0.21%—RTI Connext ProfessionalAI9/22/20269/22/2026
Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, from 7.3.0.10 before 7.3.1.6.
Awaiting AnalysisMedium (6.9)0.25%—RTI Connext ProfessionalAI9/22/20269/22/2026
Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6.
Awaiting AnalysisHigh (8.7)0.25%—RTI Connext ProfessionalAI9/22/20269/22/2026
Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from…
Awaiting AnalysisMedium (6.8)0.10%—RTI Connext ProfessionalAI9/22/20269/22/2026
Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6, from…
Awaiting AnalysisHigh (8.3)0.26%—RTI Connext ProfessionalAI9/22/20269/22/2026
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.3 before 5.2.*.
Awaiting AnalysisMedium (6.8)0.10%—RTI Connext ProfessionalAI9/22/20269/22/2026
Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6.
Awaiting AnalysisMedium (6.9)0.10%—RTI Connext ProfessionalAI9/22/20269/22/2026
Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.1.0 before 7.3.1.6.
DeferredHigh (7.1)0.42%—Frappe ErpnextAI9/20/20269/21/2026
Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise_timesheet_data, get_timesheet_detail_rate, and get_timesheet endpoints to…
DeferredMedium (4.3)0.27%—Nextcloud DeckAI9/18/20269/18/2026
The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.