Vulnerabilities

Summary — last 7 days

New vulnerabilities2,768▲ 75 vs. last week
Critical / high1,288▼ 205 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)233▲ 215 vs. last week
–

2,505 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.3)——Unfocus Scripts N StylesAI10/9/202610/9/2026
Missing Authorization vulnerability in unFocus Projects Scripts n Styles scripts-n-styles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scripts n Styles: from n/a through 3.5.8.
DeferredMedium (5.3)0.27%—Scriptkit Beam MCPAI10/8/202610/8/2026
Improper Input Validation vulnerability in BeamMCP.Schema in ScriptKittyOS beam_mcp allows an MCP client to reach a tool's dispatch function with arguments that violate the input schema the server advertised. BeamMCP.Schema.validate/2 checked type, required, additionalProperties, enum and numeric bounds on the…
Awaiting AnalysisHigh (7.8)0.15%—GhostscriptAI10/6/202610/7/2026
A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at…
DeferredCritical (9.3)0.25%—User Subscriptions FormAI10/6/202610/6/2026
Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.
DeferredHigh (8.5)0.28%—Paid Member SubscriptionsAI10/6/202610/6/2026
Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.
DeferredMedium (6.1)0.51%💥 PoCFacturascriptsAI10/5/202610/6/2026
FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the…
DeferredHigh (8.3)0.21%—ZebradAIZebra ScriptAI10/2/202610/2/2026
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network…
DeferredHigh (8.7)0.41%—ZebradAIZebra ScriptAI10/2/202610/2/2026
Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold…
Awaiting AnalysisLow (2.1)0.44%—Artifex GhostscriptAI9/30/20269/30/2026
A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might…
DeferredMedium (5.3)0.20%—Paid Member SubscriptionsAI9/30/20269/30/2026
Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.
Awaiting AnalysisLow (2.3)0.30%—Serialize JavascriptAI9/29/20269/30/2026
Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions and functions. From 7.1.1 until 7.1.2, function values serialized by serialize-javascript are not fully protected against script-closing tags in attacker-influenced function source because SCRIPT_CLOSE_REGEXP can…
Awaiting AnalysisHigh (7)0.16%—GhostscriptAI9/29/20269/30/2026
Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist by default on Windows installations, combined with Windows default ACLs allowing any…
DeferredMedium (5.9)0.19%—Nextscripts Social Networks Auto PosterAI9/27/20269/28/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials,…
DeferredMedium (6.4)0.16%—CSS Javascript ToolboxAI9/25/20269/25/2026
The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbox shortcode in all versions up to, and including, 12.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
DeferredMedium (5.3)0.21%—Cozmoslabs Paid Membership SubscriptionsAI9/23/20269/23/2026
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the request, allowing unauthenticated users to create accounts without solving the reCAPTCHA the site has enabled.
DeferredLow (3.7)0.15%—Paidmembershipssubscriptions Paid Memberships SubscriptionsAI9/23/20269/23/2026
The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment actions to the requesting user, allowing someone who holds another member's in-flight payment identifier to delete that member's checkout state.
DeferredHigh (8.8)0.66%—GhostscriptAIGnupgAISyslifters SysreptorAI9/18/20269/22/2026
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that…
DeferredMedium (4.4)0.19%—CSS Javascript ToolboxAI9/18/20269/18/2026
The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 12.0.6 via the Assignment Engine fields. This is due to insufficient input sanitization and output escaping on assignment data fields including Expressions, URLs, and Advanced assignment…
DeferredMedium (5.3)0.30%—Paidmembershipsincorporated Paid Memberships SubscriptionsAI9/17/20269/18/2026
The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount.
AnalyzedHigh (7.5)0.48%—Jenkins Script Security9/16/20269/21/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute code outside the…
AnalyzedHigh (7.5)0.29%—Jenkins Script Security9/16/20269/21/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of the first download and loading the classpath entries from the second, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins…
AnalyzedHigh (8)0.61%—Jenkins Script Security9/16/20269/21/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to…
ModifiedHigh (8.5)0.62%—Jenkins Script Security9/16/20269/26/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to execute code outside the sandbox if a suitable class is present on…
AnalyzedHigh (8.8)0.56%—Jenkins Script Security9/16/20269/21/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transformation at compile time, bypassing the sandbox protection and…
AnalyzedHigh (8.8)0.63%—Jenkins Script Security9/16/20269/21/2026
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection itself, allowing attackers with permission to define and run sandboxed scripts,…