Vulnerabilities

Summary — last 7 days

New vulnerabilities2,886▲ 263 vs. last week
Critical / high1,344▼ 85 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
–

4,643 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisCritical (9.8)0.49%—Microsoft Azure APP ServiceAI10/8/202610/10/2026
Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network.
DeferredMedium (6.5)0.20%—CAZ Informatics Services Trade INC Advancity Alms CloudAI10/8/202610/8/2026
Missing Authorization vulnerability in Caz Informatics Services Trade Inc. Advancity ALMS Cloud allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Advancity ALMS Cloud: through 2026-10-08. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
DeferredHigh (7.3)0.20%—Izometri IT Services EimzamipAI10/8/202610/8/2026
Unrestricted upload of file with dangerous type vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Using Malicious Files. This issue affects eimzamip: from v1.6.4 before v1.6.6.
DeferredLow (3.5)0.16%—Izometri IT Services EimzamipAI10/8/202610/8/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Stored XSS. This issue affects eimzamip: from v1.6.4 before v1.6.7.
Awaiting AnalysisLow (3.5)0.21%—HCL Bigfix Service ManagementAI10/6/202610/6/2026
HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to supply unexpected or malformed data, enabling processing errors, business logic bypasses, and unintended application behavior.
Awaiting AnalysisCritical (9.3)1.8%💥 ExploitAtlassian Bitbucket Data CenterAIAtlassian Confluence Data CenterAIAtlassian Jira Service Management Data CenterAIAtlassian Jira Software Data CenterAI+410/5/202610/7/2026
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web…
DeferredCritical (9.8)0.74%—Dormakaba Evolo ServiceAI10/5/202610/6/2026
An issue in dormakaba evolo Service (all versions) allows a remote attacker to execute arbitrary code as SYSTEM via a .NET component.
DeferredCritical (9.1)0.88%—Vikappointments Services Booking CalendarAI10/3/202610/6/2026
The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which…
DeferredHigh (7.1)0.18%—GG Soft Software Services PaperworkAI10/2/202610/2/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection. This issue affects Paperwork: through 2026-09-09.
DeferredHigh (7.2)0.49%—Document Merge ServiceAI10/1/202610/2/2026
Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Prior to version 9.1.0, a remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as…
AnalyzedLow (3.7)0.21%—Hcltech Bigfix Service Management10/1/202610/6/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks.
AnalyzedMedium (5.3)0.24%—Hcltech Bigfix Service Management10/1/202610/6/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks.
AnalyzedMedium (4.3)0.16%—Hcltech Bigfix Service Management10/1/202610/8/2026
HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems.
AnalyzedMedium (5.3)0.24%—Hcltech Bigfix Service Management10/1/202610/5/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks.
AnalyzedHigh (7.4)0.15%—Hcltech Bigfix Service Management10/1/202610/5/2026
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
AnalyzedMedium (5.3)0.24%—Hcltech Bigfix Service Management10/1/202610/5/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the discovery of hidden administrative API endpoints for further targeted exploitation.
AnalyzedLow (2.2)0.06%—Hcltech Bigfix Service Management10/1/202610/5/2026
HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site Request Forgery (CSRF), session hijacking via Cross-Site Scripting…
AnalyzedHigh (7.2)0.20%—Hcltech Bigfix Service Management10/1/202610/5/2026
HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hijacking and the theft of sensitive data.
Awaiting AnalysisMedium (5.7)0.11%—Canonical WSL PRO ServiceAI9/29/20269/30/2026
In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding…
DeferredHigh (8.8)0.24%💥 PoCIron Mountain Archiving Services EnvisionAI9/28/20269/28/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655.
DeferredLow (2.1)0.27%—Acrel Electric Unet WEB ServiceAI9/28/20269/28/2026
A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has…
Awaiting AnalysisCritical (9.3)0.30%—Servicenow AI PlatformAI9/24/20269/25/2026
ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security…
Awaiting AnalysisHigh (8.7)0.29%—Servicenow AI PlatformAI9/24/20269/24/2026
ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling…
Awaiting AnalysisHigh (8.7)0.27%—Servicenow AI PlatformAI9/24/20269/24/2026
ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete instance data beyond what was intended. In August 2026, ServiceNow deployed a security…
Awaiting AnalysisHigh (8.4)0.24%—Servicenow AI PlatformAI9/24/20269/25/2026
ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling…