Vulnerabilities

Summary — last 7 days

New vulnerabilities3,135▲ 554 vs. last week
Critical / high1,494▲ 89 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
–

1 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (8.8)1.2%—Xtuple Postbooks12/14/20176/17/2026
guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
Orbitaley — Vulnerabilities