Vulnerabilities
Summary — last 7 days
New vulnerabilities2,768▲ 75 vs. last week
Critical / high1,288▼ 205 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
2,505 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | — | — | Unfocus Scripts N StylesAI | 10/9/2026 | 10/9/2026 | Missing Authorization vulnerability in unFocus Projects Scripts n Styles scripts-n-styles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scripts n Styles: from n/a through 3.5.8. | |
| Deferred | Medium (5.3) | 0.27% | — | Scriptkit Beam MCPAI | 10/8/2026 | 10/8/2026 | Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the… | |
| Awaiting Analysis | High (7.8) | 0.15% | — | GhostscriptAI | 10/6/2026 | 10/7/2026 | A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at… | |
| Deferred | Critical (9.3) | 0.25% | — | User Subscriptions FormAI | 10/6/2026 | 10/6/2026 | Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions. | |
| Deferred | High (8.5) | 0.28% | — | Paid Member SubscriptionsAI | 10/6/2026 | 10/6/2026 | Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions. | |
| Deferred | Medium (6.1) | 0.51% | 💥 PoC | FacturascriptsAI | 10/5/2026 | 10/6/2026 | FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the… | |
| Deferred | High (8.3) | 0.21% | — | ZebradAIZebra ScriptAI | 10/2/2026 | 10/2/2026 | Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network… | |
| Deferred | High (8.7) | 0.41% | — | ZebradAIZebra ScriptAI | 10/2/2026 | 10/2/2026 | Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold… | |
| Awaiting Analysis | Low (2.1) | 0.44% | — | Artifex GhostscriptAI | 9/30/2026 | 9/30/2026 | A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might… | |
| Deferred | Medium (5.3) | 0.20% | — | Paid Member SubscriptionsAI | 9/30/2026 | 9/30/2026 | Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions. | |
| Awaiting Analysis | Low (2.3) | 0.30% | — | Serialize JavascriptAI | 9/29/2026 | 9/30/2026 | Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions and functions. From 7.1.1 until 7.1.2, function values serialized by serialize-javascript are not fully protected against script-closing tags in attacker-influenced function source because SCRIPT_CLOSE_REGEXP can… | |
| Awaiting Analysis | High (7) | 0.16% | — | GhostscriptAI | 9/29/2026 | 9/30/2026 | Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any… | |
| Deferred | Medium (5.9) | 0.19% | — | Nextscripts Social Networks Auto PosterAI | 9/27/2026 | 9/28/2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials,… | |
| Deferred | Medium (6.4) | 0.16% | — | CSS Javascript ToolboxAI | 9/25/2026 | 9/25/2026 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbox shortcode in all versions up to, and including, 12.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Deferred | Medium (5.3) | 0.21% | — | Cozmoslabs Paid Membership SubscriptionsAI | 9/23/2026 | 9/23/2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled. | |
| Deferred | Low (3.7) | 0.15% | — | Paidmembershipssubscriptions Paid Memberships SubscriptionsAI | 9/23/2026 | 9/23/2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state. | |
| Deferred | High (8.8) | 0.66% | — | GhostscriptAIGnupgAISyslifters SysreptorAI | 9/18/2026 | 9/22/2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that… | |
| Deferred | Medium (4.4) | 0.19% | — | CSS Javascript ToolboxAI | 9/18/2026 | 9/18/2026 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 12.0.6 via the Assignment Engine fields. This is due to insufficient input sanitization and output escaping on assignment data fields including Expressions, URLs, and Advanced assignment… | |
| Deferred | Medium (5.3) | 0.30% | — | Paidmembershipsincorporated Paid Memberships SubscriptionsAI | 9/17/2026 | 9/18/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. | |
| Analyzed | High (7.5) | 0.48% | — | Jenkins Script Security | 9/16/2026 | 9/21/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute code outside the… | |
| Analyzed | High (7.5) | 0.29% | — | Jenkins Script Security | 9/16/2026 | 9/21/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins… | |
| Analyzed | High (8) | 0.61% | — | Jenkins Script Security | 9/16/2026 | 9/21/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to… | |
| Modified | High (8.5) | 0.62% | — | Jenkins Script Security | 9/16/2026 | 9/26/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox if a suitable class is present on… | |
| Analyzed | High (8.8) | 0.56% | — | Jenkins Script Security | 9/16/2026 | 9/21/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transformation at compile time, bypassing the sandbox protection and… | |
| Analyzed | High (8.8) | 0.63% | — | Jenkins Script Security | 9/16/2026 | 9/21/2026 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attackers with permission to define and run sandboxed scripts,… |