Vulnerabilities
Summary — last 7 days
New vulnerabilities3,043▲ 582 vs. last week
Critical / high1,452▲ 283 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)393▲ 186 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (4.3) | 0.40% | — | Nirweb SupportAI | 2/3/2025 | 6/17/2026 | Authorization Bypass Through User-Controlled Key vulnerability in NirWp Team Nirweb support nirweb-support.This issue affects Nirweb support: from n/a through <= 3.0.3. | |
| Modified | Critical (9.8) | 13% | — | Nirweb Support | 5/23/2022 | 6/17/2026 | The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection |