Vulnerabilities
Summary — last 7 days
New vulnerabilities2,761▲ 61 vs. last week
Critical / high1,285▼ 211 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
224 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.8) | 0.51% | — | Code4recovery 12 Step Meeting ListAI | 8/27/2026 | 8/28/2026 | The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as… | |
| Analyzed | High (7.8) | 0.17% | — | Dell Powerprotect Cyber Recovery | 8/26/2026 | 9/1/2026 | Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection. | |
| Analyzed | High (8.8) | 0.46% | — | Dell Powerprotect Cyber Recovery | 8/26/2026 | 9/1/2026 | Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analyzed | Medium (4.3) | 0.27% | — | Dell Cloud Disaster Recovery | 8/26/2026 | 9/3/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analyzed | Medium (6.5) | 0.38% | — | Dell Powerprotect Cyber Recovery | 8/26/2026 | 9/2/2026 | Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analyzed | High (7.2) | 1.6% | — | Dell Cloud Disaster Recovery | 8/26/2026 | 9/3/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analyzed | Critical (9.1) | 2.0% | — | Dell Cloud Disaster Recovery | 8/26/2026 | 9/3/2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. | |
| Deferred | High (7.1) | 0.25% | — | Code4recovery 12 Step Meeting ListAI | 8/24/2026 | 8/24/2026 | Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions. | |
| Deferred | Medium (4.4) | 0.52% | — | SMS Alert SMS OTP FOR Woocommerce Order Notifications Abandoned Cart RecoveryAI | 7/28/2026 | 7/28/2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack… | |
| Deferred | Medium (6.5) | 0.36% | — | Villatheme Abandoned Cart Recovery FOR WoocommerceAI | 7/13/2026 | 7/13/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12. | |
| Deferred | Medium (6.9) | 0.74% | — | Vinchin Backup AND RecoveryAI | 7/9/2026 | 7/10/2026 | Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an oversized _listen_uuid field that is measured via strlen() and… | |
| Deferred | Medium (6.9) | 0.64% | — | Vinchin Backup & RecoveryAI | 7/9/2026 | 7/10/2026 | Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the agentlink_server service. Attackers can craft a malicious packet… | |
| Awaiting Analysis | Critical (9) | 2.5% | 💥 PoC | Manageengine Adselfservice PlusAIManageengine Recoverymanager PlusAIManageengine M365 Manager PlusAIManageengine Adaudit PlusAI | 6/23/2026 | 6/24/2026 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover. | |
| Deferred | High (7.2) | 0.46% | — | Cart Abandonment RecoveryAI | 6/15/2026 | 6/17/2026 | Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions. | |
| Analyzed | High (7.8) | 0.12% | — | Synology Active Backup FOR Business Recovery Media Creator | 6/3/2026 | 7/22/2026 | An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors. | |
| Awaiting Analysis | High (8.4) | 4.0% | — | Zohocorp Manageengine Adselfservice PlusAIZohocorp Manageengine Datasecurity PlusAIZohocorp Manageengine Recoverymanager PlusAI | 5/21/2026 | 7/23/2026 | Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency. | |
| Deferred | Medium (5.3) | 0.33% | — | Code4recovery 12 Step Meeting ListAI | 4/8/2026 | 7/24/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9. | |
| Deferred | Medium (6.5) | 0.37% | — | Code4recovery 12 Step Meeting ListAI | 4/8/2026 | 7/24/2026 | Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9. | |
| Analyzed | High (8.6) | 0.25% | — | Passfab Excel Password Recovery | 3/26/2026 | 6/17/2026 | PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget and shellcode that… | |
| Analyzed | High (8.6) | 0.21% | — | Passfab RAR Password Recovery | 3/26/2026 | 6/17/2026 | PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a payload with a buffer overflow, NSEH jump, and shellcode, then paste it into the 'Licensed E-mail… | |
| Analyzed | Medium (6.8) | 0.18% | — | Passfab Excel Password Recovery | 3/26/2026 | 6/17/2026 | Excel Password Recovery Professional 8.2.0.0 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long string to the 'E-Mail and Registrations Code' field. Attackers can paste a crafted payload containing 5000 bytes of data into the registration… | |
| Deferred | High (7.1) | 0.25% | — | Villatheme Abandoned Cart Recovery FOR WoocommerceAI | 3/25/2026 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Stored XSS.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.10. | |
| Analyzed | Critical (9) | 0.34% | — | N2W Backup& Recovery | 3/25/2026 | 6/17/2026 | In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution. | |
| Deferred | Medium (6.9) | 0.12% | — | Backup KEY RecoveryAI | 3/22/2026 | 6/17/2026 | Backup Key Recovery 2.2.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 or more characters into the Name field during registration to trigger a crash when submitting the form. | |
| Analyzed | Critical (9.1) | 0.18% | — | IBM DB2 Recovery Expert | 3/17/2026 | 6/17/2026 | IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission. |