Vulnerabilities
Summary — last 7 days
New vulnerabilities2,624▼ 236 vs. last week
Critical / high1,384▲ 151 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)56▼ 473 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.8) | 2.2% | — | Phpoffice Project Common | 7/15/2018 | 6/17/2026 | XMLReader.php in PHPOffice Common before 0.2.9 allows XXE. | |
| Modified | Critical (9.8) | 1.8% | — | Libstaroffice Project Libstaroffice | 6/5/2017 | 6/17/2026 | Document Liberation Project libstaroffice before 2017-04-07 has an out-of-bounds write caused by a stack-based buffer overflow related to the DatabaseName::read function in lib/StarWriterStruct.cxx. | |
| Modified | High (9.3) | 24% | — | Microsoft Office ProjectMicrosoft Project Portfolio ServerMicrosoft Project Server | 12/9/2009 | 6/16/2026 | Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability." |