Vulnerabilities

Summary — last 7 days

New vulnerabilities2,761▲ 61 vs. last week
Critical / high1,285▼ 211 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
–

224 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.8)0.51%—Code4recovery 12 Step Meeting ListAI8/27/20268/28/2026
The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as…
AnalyzedHigh (7.8)0.17%—Dell Powerprotect Cyber Recovery8/26/20269/1/2026
Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.
AnalyzedHigh (8.8)0.46%—Dell Powerprotect Cyber Recovery8/26/20269/1/2026
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalyzedMedium (4.3)0.27%—Dell Cloud Disaster Recovery8/26/20269/3/2026
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
AnalyzedMedium (6.5)0.38%—Dell Powerprotect Cyber Recovery8/26/20269/2/2026
Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
AnalyzedHigh (7.2)1.6%—Dell Cloud Disaster Recovery8/26/20269/3/2026
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
AnalyzedCritical (9.1)2.0%—Dell Cloud Disaster Recovery8/26/20269/3/2026
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
DeferredHigh (7.1)0.25%—Code4recovery 12 Step Meeting ListAI8/24/20268/24/2026
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
DeferredMedium (4.4)0.52%—SMS Alert SMS OTP FOR Woocommerce Order Notifications Abandoned Cart RecoveryAI7/28/20267/28/2026
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and lack…
DeferredMedium (6.5)0.36%—Villatheme Abandoned Cart Recovery FOR WoocommerceAI7/13/20267/13/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.
DeferredMedium (6.9)0.74%—Vinchin Backup AND RecoveryAI7/9/20267/10/2026
Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an oversized _listen_uuid field that is measured via strlen() and…
DeferredMedium (6.9)0.64%—Vinchin Backup & RecoveryAI7/9/20267/10/2026
Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the agentlink_server service. Attackers can craft a malicious packet…
Awaiting AnalysisCritical (9)2.5%💥 PoCManageengine Adselfservice PlusAIManageengine Recoverymanager PlusAIManageengine M365 Manager PlusAIManageengine Adaudit PlusAI6/23/20266/24/2026
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
DeferredHigh (7.2)0.46%—Cart Abandonment RecoveryAI6/15/20266/17/2026
Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.
AnalyzedHigh (7.8)0.12%—Synology Active Backup FOR Business Recovery Media Creator6/3/20267/22/2026
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
Awaiting AnalysisHigh (8.4)4.0%—Zohocorp Manageengine Adselfservice PlusAIZohocorp Manageengine Datasecurity PlusAIZohocorp Manageengine Recoverymanager PlusAI5/21/20267/23/2026
Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency.
DeferredMedium (5.3)0.33%—Code4recovery 12 Step Meeting ListAI4/8/20267/24/2026
Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9.
DeferredMedium (6.5)0.37%—Code4recovery 12 Step Meeting ListAI4/8/20267/24/2026
Missing Authorization vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 12 Step Meeting List: from n/a through <= 3.19.9.
AnalyzedHigh (8.6)0.25%—Passfab Excel Password Recovery3/26/20266/17/2026
PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget and shellcode that…
AnalyzedHigh (8.6)0.21%—Passfab RAR Password Recovery3/26/20266/17/2026
PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a payload with a buffer overflow, NSEH jump, and shellcode, then paste it into the 'Licensed E-mail…
AnalyzedMedium (6.8)0.18%—Passfab Excel Password Recovery3/26/20266/17/2026
Excel Password Recovery Professional 8.2.0.0 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long string to the 'E-Mail and Registrations Code' field. Attackers can paste a crafted payload containing 5000 bytes of data into the registration…
DeferredHigh (7.1)0.25%—Villatheme Abandoned Cart Recovery FOR WoocommerceAI3/25/20266/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Stored XSS.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.10.
AnalyzedCritical (9)0.34%—N2W Backup& Recovery3/25/20266/17/2026
In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.
DeferredMedium (6.9)0.12%—Backup KEY RecoveryAI3/22/20266/17/2026
Backup Key Recovery 2.2.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a buffer of 300 or more characters into the Name field during registration to trigger a crash when submitting the form.
AnalyzedCritical (9.1)0.18%—IBM DB2 Recovery Expert3/17/20266/17/2026
IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for verifying the integrity of the data during transmission.
Orbitaley — Vulnerabilities