Vulnerabilities
Summary — last 7 days
New vulnerabilities2,759▲ 5 vs. last week
Critical / high1,275▼ 253 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)242▲ 224 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.5) | 0.34% | — | ShopkitAI | 9/16/2024 | 6/17/2026 | A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shopping cart via the qtd parameter in the add-to-cart function. | |
| Modified | Medium (5.3) | 0.44% | — | Wiloke Myshopkit | 2/26/2024 | 6/17/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit.This issue affects WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit: from n/a through 1.0.9. | |
| Modified | Medium (6.1) | 0.44% | — | Myshopkit Winters | 10/20/2023 | 6/17/2026 | The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Modified | Medium (6.1) | 0.73% | — | Shopkit Project Shopkit | 9/24/2021 | 6/17/2026 | Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field. |