Vulnerabilities

Summary — last 7 days

New vulnerabilities2,823▼ 249 vs. last week
Critical / high1,318▼ 180 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
–

1 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.1)1.5%—Ssp-europe Secure Data Space1/11/20166/17/2026
Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to api/v3/public/shares/downloads/, the (2) authType parameter to api/v3/auth/login, or the (3) login parameter to api/v3/auth/reset_password.