Vulnerabilities
Summary — last 7 days
New vulnerabilities2,739▼ 501 vs. last week
Critical / high1,301▼ 201 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 277 vs. last week
82 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (7.6) | 0.21% | — | Pcre2AI | 9/30/2026 | 10/3/2026 | PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data. | |
| Undergoing Analysis | Low (3.3) | 0.16% | — | Pcre2 | 9/11/2026 | 9/16/2026 | In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe. | |
| Undergoing Analysis | High (7.8) | 0.13% | — | Pcre2 | 9/11/2026 | 9/16/2026 | In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur. | |
| Analyzed | Medium (6.5) | 0.27% | — | Pcre2 | 9/11/2026 | 9/16/2026 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject. | |
| Analyzed | Medium (6.5) | 0.25% | — | Pcre2 | 9/11/2026 | 9/16/2026 | PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. | |
| Analyzed | High (7.4) | 0.28% | — | Pcre2 | 9/11/2026 | 9/16/2026 | PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern. | |
| Analyzed | Medium (5.9) | 0.29% | — | Pcre2 | 9/11/2026 | 9/16/2026 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data. | |
| Deferred | High (8.2) | 0.39% | — | Pcre2AI | 9/5/2026 | 9/9/2026 | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a… | |
| Modified | High (7.8) | 0.17% | — | Deepcool Deepcreative | 4/20/2026 | 7/5/2026 | Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file | |
| Deferred | Critical (9.8) | 0.38% | — | PrestashopAIAdvancedpopupcreatorAI | 2/13/2026 | 6/17/2026 | A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized… | |
| Analyzed | Medium (6.9) | 0.80% | — | Pcre2 | 8/27/2025 | 6/17/2026 | The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in… | |
| Deferred | Medium (6.5) | 0.36% | — | Devscred ShopcredAI | 4/1/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred ShopCred shopcred allows DOM-Based XSS.This issue affects ShopCred: from n/a through <= 1.3.0. | |
| Deferred | High (7.1) | 0.30% | — | Wrenchpilot Essay Wizard WpcresAI | 3/3/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wrenchpilot Essay Wizard (wpCRES) essay-wizard-wpcres allows Reflected XSS.This issue affects Essay Wizard (wpCRES): from n/a through <= 1.0.6.4. | |
| Deferred | Medium (6.4) | 0.30% | — | Pcrecruiter ExtensionsAI | 12/20/2024 | 6/17/2026 | The PCRecruiter Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PCRecruiter' shortcode in all versions up to, and including, 1.4.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Deferred | Medium (4.3) | 0.28% | — | Wpcreativeidea Advanced Testimonial Carousel FOR ElementorAI | 6/9/2024 | 6/17/2026 | Missing Authorization vulnerability in wpcreativeidea Advanced Testimonial Carousel for Elementor.This issue affects Advanced Testimonial Carousel for Elementor: from n/a through 3.0.0. | |
| Modified | Medium (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 11/15/2023 | 6/17/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modified | High (7.5) | 1.1% | — | Pcre2 | 7/18/2023 | 6/17/2026 | Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input. | |
| Modified | Medium (4.8) | 0.39% | — | Snapcreek EZP Coming Soon Page | 4/7/2023 | 6/17/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Coming Soon Page plugin <= 1.0.7.3 versions. | |
| Modified | Critical (9.1) | 2.8% | — | Pcre2Redhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+8 | 5/16/2022 | 6/17/2026 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers. | |
| Analyzed | Critical (9.1) | 3.4% | — | Pcre2Fedoraproject FedoraRedhat Enterprise LinuxNetapp Active IQ Unified Manager+9 | 5/16/2022 | 6/17/2026 | An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching… | |
| Modified | Medium (5.3) | 4.2% | — | PcreApple MacosGitlabOracle Communications Cloud Native Core Policy+11 | 6/15/2020 | 6/17/2026 | libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring. | |
| Modified | High (7.5) | 2.8% | — | PcreApple MacosSplunk Universal Forwarder | 6/15/2020 | 6/17/2026 | libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454. | |
| Modified | High (7.5) | 1.6% | — | Pcre2Fedoraproject FedoraSplunk Universal Forwarder | 2/14/2020 | 6/17/2026 | An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in… | |
| Modified | Medium (5.5) | 1.6% | — | PcreOpensuseMariadbPHP | 1/14/2020 | 6/17/2026 | The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/". | |
| Modified | High (7.8) | 1.6% | — | PcreOpensuseMariadbPHP | 1/14/2020 | 6/17/2026 | The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times… |