Vulnerabilities

Summary — last 7 days

New vulnerabilities3,072▲ 483 vs. last week
Critical / high1,456▲ 55 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
–

1,924 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ReceivedHigh (7.5)0.56%—Elicus Divi PlusAI10/10/202610/10/2026
The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permission callback (SVGAnimatorController::index_permission) returning true…
ReceivedHigh (7.2)0.25%—Wppa WP Photo Album PlusAI10/10/202610/10/2026
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
ReceivedMedium (5.4)0.23%—Hello PlusAI10/10/202610/10/2026
The Hello Plus plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to publish…
Awaiting AnalysisMedium (6)0.18%—Mongodb C Plus Plus DriverAI10/8/202610/8/2026
The MongoDB C++ Driver discards content after an embedded NUL byte in certain field and collection names accepted by the collection API. This can cause the driver and the calling application to interpret the same name differently. An authenticated actor who can influence a name passed by an affected application can…
DeferredHigh (7.6)0.23%—Gopiplus Post Title Marquee ScrollAI10/7/202610/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopiplus Post title marquee scroll post-title-marquee-scroll allows Blind SQL Injection.This issue affects Post title marquee scroll: from n/a through 9.9.
Awaiting AnalysisHigh (7.5)0.13%—AMD Zynq Ultrascale Plus MpsocAIAMD RfsocAI10/5/202610/6/2026
Insufficient boundary validation in the USB boot mode implementation of AMD Zynq™ UltraScale+ MPSoC and RFSoC devices could allow unbounded Device Firmware Upgrade (DFU) download requests to overflow the DDR receive buffer into FSBL memory, potentially resulting in unauthorized code execution during the boot process.…
DeferredMedium (6.4)0.19%—Responsive PlusAI10/3/202610/6/2026
The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
DeferredHigh (7.7)0.23%—Tp-link Deco M9 PlusAI10/1/202610/1/2026
A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x91 handler. Successful exploitation may allow an adjacent, unauthenticated…
Awaiting AnalysisMedium (5.3)0.24%—AJA Helo PlusAI9/30/202610/1/2026
AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting an unsanitized eParamID_SystemName value through the /config?action=set web configuration API. Attackers can exploit this flaw…
DeferredHigh (8.7)0.38%—AJA Helo PlusAI9/30/20269/30/2026
AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse engineer the publicly available firmware image…
DeferredMedium (6.5)0.18%—THE Plus AddonsAI9/30/20269/30/2026
Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions.
DeferredMedium (6.5)0.21%—Wppa WP Photo Album PlusAI9/30/20269/30/2026
Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.
DeferredHigh (8.7)0.30%—Nicotine-plus Nicotine+AI9/29/20269/30/2026
Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a decompression bomb, exhausting available memory of the recipient's operating system. This issue has been patched in version 3.3.11.
DeferredHigh (8.8)0.40%—Convertplug ConvertplusAI9/28/20269/29/2026
The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the…
DeferredHigh (8.8)0.27%—Bimser EBA PlusAI9/28/20269/28/2026
Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web Shell to a Web Server. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
DeferredMedium (5.4)0.15%—Bimser EBA PlusAI9/28/20269/28/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Stored XSS. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
DeferredMedium (6.5)0.29%—Bimser EBA PlusAI9/28/20269/28/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Path Traversal. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.
DeferredHigh (7.7)0.80%—EyeplusAI9/28/20269/28/2026
A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
DeferredMedium (5.5)0.29%—EyeplusAI9/28/202610/1/2026
A flaw has been found in Eyeplus 57.0.0.0308. The impacted element is an unknown function of the file /snapshot of the component p2pcam Service. This manipulation causes information disclosure. The attack is possible to be carried out remotely. The exploit has been published and may be used.
DeferredMedium (5.5)0.29%—EyeplusAI9/28/20269/28/2026
A vulnerability was detected in Eyeplus 57.0.0.0308. The affected element is the function GetUsers of the file /onvif/Device of the component ONVIF. The manipulation results in information disclosure. The attack can be executed remotely. The exploit is now public and may be used.
DeferredMedium (5.3)0.19%—UpdraftplusAI9/27/20269/28/2026
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 2.26.8.26 does not have any capability check in a routine that outputs its stored remote storage settings into admin pages when the site is left in a particular post-migration…
DeferredMedium (6.4)0.19%—Wordplus Better MessagesAI9/25/20269/25/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via User Display Name in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for…
DeferredMedium (6.5)0.27%—Wordplus Better MessagesAI9/25/20269/25/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' Message Meta Parameter in all versions up to, and including, 3.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
Awaiting AnalysisHigh (8.5)1.0%—Netgate Pfsense PlusAINetgate Pfsense CEAI9/25/20269/30/2026
In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write…
DeferredHigh (7.1)0.19%—Wppa WP Photo Album PlusAI9/23/20269/23/2026
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.
Orbitaley — Vulnerabilities