Vulnerabilities
Summary — last 7 days
New vulnerabilities2,732▼ 549 vs. last week
Critical / high1,295▼ 233 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)244▼ 258 vs. last week
121 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.5) | 0.50% | — | Admin Safety GuardAI | 8/8/2026 | 8/26/2026 | The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability check on one of its REST API endpoints, allowing unauthenticated attackers to retrieve the full list of registered users including their usernames, email addresses, roles,… | |
| Awaiting Analysis | High (8.2) | 0.61% | — | Nasa Core Flight SystemAINasa Health AND SafetyAI | 7/30/2026 | 8/31/2026 | An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a… | |
| Awaiting Analysis | High (8.2) | 0.61% | — | Nasa Core Flight SystemAINasa Health AND SafetyAI | 7/16/2026 | 7/17/2026 | A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service. | |
| Deferred | Low (2.1) | 0.45% | — | Sourcecodester Safety Anger PADAI | 4/28/2026 | 6/17/2026 | A vulnerability was found in SourceCodester Safety Anger Pad 1.0. The affected element is an unknown function. The manipulation of the argument angerDisplay results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Deferred | High (8.1) | 0.48% | — | Themepaste Admin Safety GuardAI | 3/19/2026 | 6/17/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-guard allows Password Recovery Exploitation.This issue affects Admin Safety Guard: from n/a through <= 1.2.6. | |
| Analyzed | Medium (5.1) | 0.35% | — | Etaplighting Etap Safety Manager | 12/30/2025 | 6/17/2026 | ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows unauthenticated attackers to inject malicious HTML and JavaScript. Attackers can craft specially formed requests to execute arbitrary scripts in victim browser sessions, potentially stealing credentials… | |
| Analyzed | High (7.5) | 0.31% | — | Flocksafety License Plate Reader Firmware | 10/2/2025 | 6/17/2026 | Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware. | |
| Analyzed | Critical (9.8) | 0.67% | — | Flocksafety Flock Safety | 10/2/2025 | 6/17/2026 | The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) bundles a Java Keystore (flock_rye.bks) along with its hardcoded password (flockhibiki17) in its code. The keystore contains a… | |
| Analyzed | Medium (6.2) | 0.17% | — | Flocksafety Flock Safety | 10/2/2025 | 6/17/2026 | The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has a cleartext Auth0 client secret in its codebase. Because application binaries can be trivially decompiled or inspected, attackers can… | |
| Analyzed | High (7.5) | 0.47% | — | Flocksafety Flock Safety | 10/2/2025 | 6/17/2026 | The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) contains a cleartext DataDog API key within in its codebase. Because application binaries can be trivially decompiled or inspected,… | |
| Modified | Critical (9.8) | 1.1% | — | Flocksafety Flock Safety | 10/2/2025 | 6/17/2026 | The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsible for the camera feed on Falcon, Sparrow, and Bravo devices, but exposes administrative API endpoints on port 8080 without authentication. Endpoints include but are not limited… | |
| Analyzed | High (7.3) | 0.25% | — | Flocksafety Bravo Compute BOX Firmware | 9/25/2025 | 6/17/2026 | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with Secure Boot disabled. This allows an attacker to flash modified firmware with no cryptographic protections. | |
| Analyzed | High (7.5) | 0.43% | — | Flocksafety Bravo Compute BOX Firmware | 9/25/2025 | 6/17/2026 | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with its bootloader unlocked. This permits bypass of Android Verified Boot (AVB) and allows direct modification of partitions. | |
| Analyzed | Medium (5.4) | 0.23% | — | Flocksafety Bravo Compute BOX Firmware | 9/25/2025 | 6/17/2026 | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL mode. This enables attackers with physical access to flash arbitrary firmware, dump partitions, and bypass bootloader and OS security controls. | |
| Deferred | Medium (5.9) | 0.22% | — | Tomas Cordero Safety ExitAI | 9/22/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomas Cordero Safety Exit safety-exit allows Stored XSS.This issue affects Safety Exit: from n/a through <= 1.8.0. | |
| Deferred | High (8.5) | 0.18% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAISiemens Simocode ESAI+5 | 8/12/2025 | 6/17/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC STEP 7 V20 (All versions < V20 Update 4), SIMATIC WinCC V17 (All versions < V17 Update 9), SIMATIC… | |
| Deferred | High (8.6) | 0.17% | — | Siemens Simatic PCS NEOAISiemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAI+7 | 8/12/2025 | 6/17/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All… | |
| Analyzed | Low (2.4) | 0.15% | — | Flocksafety License Plate Reader Firmware | 6/27/2025 | 6/17/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code. | |
| Analyzed | Medium (4.6) | 0.24% | — | Flocksafety License Plate Reader Firmware | 6/27/2025 | 6/17/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system. | |
| Analyzed | Medium (6.8) | 0.25% | — | Flocksafety License Plate Reader Firmware | 6/27/2025 | 6/17/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control. | |
| Analyzed | Medium (4.6) | 0.23% | — | Flocksafety Gunshot Detection Firmware | 6/27/2025 | 6/17/2026 | Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system. | |
| Analyzed | Low (2.4) | 0.16% | — | Flocksafety Gunshot Detection Firmware | 6/27/2025 | 6/17/2026 | Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code. | |
| Analyzed | Medium (6.8) | 0.26% | — | Flocksafety Gunshot Detection Firmware | 6/27/2025 | 6/17/2026 | Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control. | |
| Analyzed | Medium (4.6) | 0.24% | — | Flocksafety Gunshot Detection Firmware | 6/27/2025 | 6/17/2026 | Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection. | |
| Deferred | High (8.2) | 0.41% | — | Siemens Sirius 3rk3 Modular Safety SystemAISiemens Sirius 3sk2 Safety RelaysAI | 5/13/2025 | 6/17/2026 | A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). The affected devices do not require authentication to access critical resources. An attacker with network access could retrieve sensitive information from certain data records,… |