Vulnerabilities
Summary — last 7 days
New vulnerabilities2,871▲ 247 vs. last week
Critical / high1,338▼ 91 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (4.3) | 1.1% | — | Openedit Digital Asset Management | 2/23/2009 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in data/views/index.html in OpenEdit Digital Asset Management (DAM) before 5.2014 allows remote attackers to inject arbitrary web script or HTML via the catalogid parameter. | |
| Modified | Medium (6.8) | 0.58% | — | Openedit Digital Asset Management | 2/23/2009 | 6/16/2026 | Cross-site request forgery (CSRF) vulnerability in OpenEdit Digital Asset Management (DAM) before 5.2014 allows remote attackers to perform unspecified actions as arbitrary users via unknown vectors. | |
| Modified | Medium (4.3) | 1.1% | — | Openedit Digital Asset Management | 2/23/2009 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in archive/savedqueries/savequeryfinish.html in OpenEdit Digital Asset Management (DAM) before 5.2014 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modified | Medium (6.8) | 2.0% | 💥 Exploit | Openedit INC Openedit | 12/22/2005 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) oe-action and (2) page parameters. |