Vulnerabilities

Summary — last 7 days

New vulnerabilities2,772▲ 13 vs. last week
Critical / high1,288▼ 242 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
–

18 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.5)0.86%—Selenium10/15/20236/17/2026
NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.
ModifiedMedium (6.1)0.41%—Selenium Grid7/5/20236/17/2026
A cross-site scripting (XSS) vulnerability in Selenium Grid v3.141.59 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the hub parameter under the /grid/console page.
ModifiedHigh (8.8)12%—Selenium Grid4/19/20226/17/2026
Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.
ModifiedHigh (8.8)1.1%—Selenium Grid4/15/20226/17/2026
Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The impact is: execute arbitrary code (remote). The component is: WebDriver endpoint of Selenium Grid / Selenium Standalone Server. The attack vector is: Triggered by browsing to to a malicious remote web…
ModifiedMedium (4.3)43%—Jenkins Selenium Html Report6/30/20216/17/2026
Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModifiedHigh (8)0.94%—Jenkins Selenium6/3/20206/17/2026
Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions provided by the plugin.
ModifiedHigh (8.1)1.7%—Windows-seleniumjar Project Windows-seleniumjar6/4/20186/17/2026
windows-seleniumjar is a module that downloads the Selenium Jar file windows-seleniumjar downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is…
ModifiedHigh (8.1)1.8%—Windows-selenium-chromedriver Project Windows-selenium-chromedriver6/4/20186/17/2026
windows-selenium-chromedriver is a module that downloads the Selenium Jar file. windows-selenium-chromedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled…
ModifiedHigh (8.1)1.7%—Windows-seleniumjar-mirror Project Windows-seleniumjar-mirror6/4/20186/17/2026
windows-seleniumjar-mirror downloads the Selenium Jar file windows-seleniumjar-mirror downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on…
ModifiedHigh (8.1)1.8%—Selenium-portal Project Selenium-portal6/4/20186/17/2026
selenium-portal is a Selenium Testing Framework selenium-portal downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or…
ModifiedHigh (8.1)2.1%—Selenium-wrapper Project Selenium-wrapper6/1/20186/17/2026
selenium-wrapper is a selenium server wrapper, including installation and chrome webdriver. selenium-wrapper downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary…
ModifiedHigh (8.1)2.1%—Selenium-chromedriver Project Selenium-chromedriver6/1/20186/17/2026
selenium-chromedriver is a simple utility for downloading the Selenium Webdriver for Google Chrome selenium-chromedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker…
ModifiedHigh (8.1)2.0%—Selenium-standalone-painful Project Selenium-standalone-painful5/29/20186/17/2026
selenium-standalone-painful installs a start-selenium command line to start a standalone selenium server with chrome-driver. selenium-standalone-painful downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the…
ModifiedHigh (8.1)1.7%—Spunjs Selenium-binaries5/29/20186/17/2026
selenium-binaries downloads Selenium related binaries for your OS. selenium-binaries downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on…
ModifiedHigh (8.1)1.7%—Groupon Selenium-download5/29/20186/17/2026
selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an…
ModifiedMedium (6.8)1.7%💥 ExploitBiba Software Seleniumserver WEB Server11/26/20066/16/2026
Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModifiedHigh (10)2.7%—Biba Software Seleniumserver FTP Server11/20/20066/16/2026
SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to obtain passwords by reading the file. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
ModifiedMedium (6.4)1.6%—Biba Software Seleniumserver FTP Server11/20/20066/16/2026
Multiple directory traversal vulnerabilities in SeleniumServer FTP Server 1.0, and possibly earlier, allow remote attackers to list arbitrary directories, read arbitrary files, and upload arbitrary files via directory traversal sequences in the (1) DIR (LIST or NLST), (2) GET (RETR), and (3) PUT (STOR) commands.
Orbitaley — Vulnerabilities