Vulnerabilities
Summary — last 7 days
New vulnerabilities2,744▲ 67 vs. last week
Critical / high1,456▲ 350 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)92▼ 421 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.1) | 0.29% | — | Igniterealtime OpenfireAIOpenfire Nodejs PluginAI | 1/26/2026 | 6/17/2026 | Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration… |