Vulnerabilities

Summary — last 7 days

New vulnerabilities2,739▼ 501 vs. last week
Critical / high1,301▼ 201 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 277 vs. last week
–

82 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (7.6)0.21%—Pcre2AI9/30/202610/3/2026
PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
Undergoing AnalysisLow (3.3)0.16%—Pcre29/11/20269/16/2026
In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.
Undergoing AnalysisHigh (7.8)0.13%—Pcre29/11/20269/16/2026
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
AnalyzedMedium (6.5)0.27%—Pcre29/11/20269/16/2026
PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.
AnalyzedMedium (6.5)0.25%—Pcre29/11/20269/16/2026
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
AnalyzedHigh (7.4)0.28%—Pcre29/11/20269/16/2026
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.
AnalyzedMedium (5.9)0.29%—Pcre29/11/20269/16/2026
PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.
DeferredHigh (8.2)0.39%—Pcre2AI9/5/20269/9/2026
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a…
ModifiedHigh (7.8)0.17%—Deepcool Deepcreative4/20/20267/5/2026
Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file
DeferredCritical (9.8)0.38%—PrestashopAIAdvancedpopupcreatorAI2/13/20266/17/2026
A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execute arbitrary SQL queries via the fromController parameter in the popup controller. The parameter is passed unsanitized…
AnalyzedMedium (6.9)0.80%—Pcre28/27/20256/17/2026
The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString) verb when combined with (*ACCEPT) in…
DeferredMedium (6.5)0.36%—Devscred ShopcredAI4/1/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred ShopCred shopcred allows DOM-Based XSS.This issue affects ShopCred: from n/a through <= 1.3.0.
DeferredHigh (7.1)0.30%—Wrenchpilot Essay Wizard WpcresAI3/3/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wrenchpilot Essay Wizard (wpCRES) essay-wizard-wpcres allows Reflected XSS.This issue affects Essay Wizard (wpCRES): from n/a through <= 1.0.6.4.
DeferredMedium (6.4)0.30%—Pcrecruiter ExtensionsAI12/20/20246/17/2026
The PCRecruiter Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PCRecruiter' shortcode in all versions up to, and including, 1.4.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
DeferredMedium (4.3)0.28%—Wpcreativeidea Advanced Testimonial Carousel FOR ElementorAI6/9/20246/17/2026
Missing Authorization vulnerability in wpcreativeidea Advanced Testimonial Carousel for Elementor.This issue affects Advanced Testimonial Carousel for Elementor: from n/a through 3.0.0.
ModifiedMedium (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3511/15/20236/17/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModifiedHigh (7.5)1.1%—Pcre27/18/20236/17/2026
Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.
ModifiedMedium (4.8)0.39%—Snapcreek EZP Coming Soon Page4/7/20236/17/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Coming Soon Page plugin <= 1.0.7.3 versions.
ModifiedCritical (9.1)2.8%—Pcre2Redhat Enterprise LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+85/16/20226/17/2026
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
AnalyzedCritical (9.1)3.4%—Pcre2Fedoraproject FedoraRedhat Enterprise LinuxNetapp Active IQ Unified Manager+95/16/20226/17/2026
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching…
ModifiedMedium (5.3)4.2%—PcreApple MacosGitlabOracle Communications Cloud Native Core Policy+116/15/20206/17/2026
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
ModifiedHigh (7.5)2.8%—PcreApple MacosSplunk Universal Forwarder6/15/20206/17/2026
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
ModifiedHigh (7.5)1.6%—Pcre2Fedoraproject FedoraSplunk Universal Forwarder2/14/20206/17/2026
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in…
ModifiedMedium (5.5)1.6%—PcreOpensuseMariadbPHP1/14/20206/17/2026
The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".
ModifiedHigh (7.8)1.6%—PcreOpensuseMariadbPHP1/14/20206/17/2026
The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times…
Orbitaley — Vulnerabilities