Vulnerabilities

Summary — last 7 days

New vulnerabilities2,771▼ 1 vs. last week
Critical / high1,280▼ 248 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 211 vs. last week
–

27 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.1)0.29%—Image Sizes ON DemandAI6/24/20266/29/2026
The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
DeferredMedium (4.3)0.22%—Creativemindssolutions CM ON Demand Search AND ReplaceAI12/16/202510/7/2026
Missing Authorization vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-replace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM On Demand Search And Replace: from n/a through <= 1.5.5.
DeferredMedium (4.3)0.13%—Creativemindssolutions CM ON Demand Search AND ReplaceAI8/14/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-replace allows Cross Site Request Forgery.This issue affects CM On Demand Search And Replace: from n/a through <= 1.5.2.
DeferredMedium (5.9)0.18%—Creativemindssolutions CM ON Demand Search AND ReplaceAI8/14/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-search-and-replace allows Stored XSS.This issue affects CM On Demand Search And Replace: from n/a through <= 1.5.2.
ModifiedMedium (5.5)0.22%—Intel ON Demand11/14/20236/17/2026
Insertion of sensitive information into log file in some Intel(R) On Demand software before versions 1.16.2, 2.1.1, 3.1.0 may allow an authenticated user to potentially enable information disclosure via local access.
ModifiedMedium (5.4)0.62%—Jenkins Fortify ON Demand7/2/20206/17/2026
A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.
ModifiedMedium (4.3)0.66%—Jenkins Fortify ON Demand7/2/20206/17/2026
A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.
ModifiedMedium (4.3)0.69%—Jenkins Fortify ON Demand7/2/20206/17/2026
A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
ModifiedHigh (7.5)3.1%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+66/10/20206/17/2026
Certain IBM Aspera applications are vulnerable to buffer overflow after valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code through a service. IBM X-Force ID: 180902.
ModifiedHigh (7.5)1.6%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+66/10/20206/17/2026
Certain IBM Aspera applications are vulnerable to arbitrary memory corruption based on the product configuration, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180901.
ModifiedHigh (7.5)2.6%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+66/10/20206/17/2026
Certain IBM Aspera applications are vulnerable to buffer overflow based on the product configuration and valid authentication, which could allow an attacker with intimate knowledge of the system to execute arbitrary code or perform a denial-of-service (DoS) through the http fallback service. IBM X-Force ID: 180900.
ModifiedHigh (7.5)5.1%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+66/10/20206/17/2026
Certain IBM Aspera applications are vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker with intimate knowledge of the server to execute arbitrary code on the system with the privileges of root or cause server to crash. IBM X-Force ID: 180814.
ModifiedHigh (7.5)3.4%—IBM Aspera Application Platform ON DemandIBM Aspera Faspex ON DemandIBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server+66/10/20206/17/2026
Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API. IBM X-Force ID: 180810.
ModifiedHigh (8.8)0.68%—Jenkins Fortify ON Demand10/16/20196/17/2026
Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
ModifiedHigh (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+518/5/20196/17/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModifiedMedium (6.5)1.5%—Jenkins Fortify ON Demand Uploader3/28/20196/17/2026
A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
ModifiedMedium (6.5)1.3%—Jenkins Fortify ON Demand Uploader3/28/20196/17/2026
A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection to an attacker-specified server.
ModifiedCritical (9.8)1.7%—Pivotal Software Broker APIPivotal Software ON Demand Services SDK11/19/20186/17/2026
Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with different credentials, allowing them to infer valid credentials and gain access to perform broker…
ModifiedCritical (9.8)3.0%💥 ExploitON Demand Marketplace Script Project ON Demand Marketplace Script12/13/20176/17/2026
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
ModifiedMedium (6.1)0.77%—IBM Host On-demand1/18/20166/17/2026
Cross-site scripting (XSS) vulnerability in IBM Host On-Demand 11.0 through 11.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModifiedHigh (7.1)25%💥 PoCIBM JavaOracle JDKOracle JREOracle Jrockit+117/23/20136/16/2026
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8…
ModifiedHigh (9.3)6.9%—IBM JavaIBM Lotus DominoIBM Lotus NotesIBM Lotus Notes Sametime+121/11/20136/16/2026
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control…
ModifiedHigh (9.3)6.9%—IBM JavaIBM Lotus DominoIBM Lotus NotesIBM Lotus Notes Sametime+121/11/20136/16/2026
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli…
ModifiedHigh (9.3)6.9%—IBM JavaIBM Lotus DominoIBM Lotus NotesIBM Lotus Notes Sametime+121/11/20136/16/2026
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli…
ModifiedHigh (9.3)5.1%—IBM JavaIBM Lotus DominoIBM Lotus NotesIBM Lotus Notes Sametime+121/11/20136/16/2026
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control…