Vulnerabilities
Summary — last 7 days
New vulnerabilities2,720▼ 353 vs. last week
Critical / high1,288▼ 193 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)216▼ 113 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (5.4) | 0.27% | — | Sentinels Randomizer Project Sentinels Randomizer | 9/30/2014 | 6/17/2026 | The Sentinels Randomizer (aka com.mikehipps.sentinelsrandomizer) application 1.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modified | Medium (4.3) | 1.0% | — | Drupal Randomizer | 1/12/2010 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in the Randomizer module 5.x through 5.x-1.0 and 6.x through 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modified | Medium (6.8) | 4.0% | 💥 Exploit | PHP Multi User Randomizer | 5/13/2007 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attackers to inject arbitrary web script or HTML via (1) the edit_plugin parameter to configure_plugin.tpl.php, or (2) certain array parameters to web/phpinfo.php, as demonstrated by 1[] or a[]. |