Vulnerabilities
Summary — last 7 days
New vulnerabilities2,783▲ 27 vs. last week
Critical / high1,477▲ 294 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)68▼ 441 vs. last week
1,785 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (7.8) | 0.13% | — | Rapid7 InsightvmAI | 9/24/2026 | 9/26/2026 | An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Assessment content at or below version 0.0.261.0 included a check that invoked the… | |
| Awaiting Analysis | Critical (9.8) | 0.52% | — | Fortinet FortimonitoronsightAI | 9/11/2026 | 9/11/2026 | A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here> | |
| Analyzed | High (7.2) | 1.0% | — | Microsoft Azure Hdinsight | 9/8/2026 | 9/23/2026 | Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network. | |
| Deferred | High (8.3) | 0.17% | — | Milesight IOT DevicesAI | 8/26/2026 | 9/9/2026 | A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The… | |
| Modified | Medium (6.5) | 0.16% | — | Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client | 8/12/2026 | 9/5/2026 | A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount… | |
| Modified | High (7.7) | 0.50% | — | Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client | 8/11/2026 | 9/5/2026 | A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every… | |
| Modified | Medium (6.8) | 0.69% | — | Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client | 8/11/2026 | 9/5/2026 | A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability… | |
| Modified | Medium (6.5) | 0.16% | — | Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client | 8/11/2026 | 9/5/2026 | A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized… | |
| Awaiting Analysis | Medium (6.5) | 0.24% | — | SssdAIRedhat Insights-coreAIClusterlabs PacemakerAI | 8/11/2026 | 8/14/2026 | A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in archives uploaded to console.redhat.com. | |
| Analyzed | High (8.8) | 1.0% | — | Microsoft Application Insights Profiler | 8/7/2026 | 8/17/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | |
| Deferred | Critical (10) | 0.52% | — | Monsterinsights PROAI | 8/6/2026 | 8/26/2026 | The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all… | |
| Analyzed | Medium (5.3) | 0.40% | — | IBM Business Automation Insights | 8/5/2026 | 8/10/2026 | IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files. | |
| Awaiting Analysis | Critical (9.3) | 1.4% | — | Keysight Ixchariot EndpointAI | 8/4/2026 | 8/26/2026 | Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges. | |
| Awaiting Analysis | Critical (9.3) | 1.3% | — | Keysight Ixchariot EndpointAI | 8/4/2026 | 8/26/2026 | Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code. | |
| Awaiting Analysis | Critical (9.3) | 1.3% | — | Keysight Ixchariot EndpointAI | 8/4/2026 | 8/26/2026 | Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code. | |
| Deferred | Low (3.7) | 0.25% | — | MonsterinsightsAI | 8/4/2026 | 8/26/2026 | The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before 11.1.0 is not connected to Google Analytics the HMAC signing key is empty, which lets unauthenticated attackers forge a valid… | |
| Awaiting Analysis | High (7.8) | 0.16% | — | Rapid7 InsightvmAIRapid7 NexposeAIRapid7 Insight AgentAI | 7/24/2026 | 7/30/2026 | Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight… | |
| Awaiting Analysis | Medium (4.8) | 0.38% | — | Rapid7 Insightconnect Markdown PluginAI | 6/26/2026 | 7/24/2026 | Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbitrary outbound HTTP requests via unsanitized resource-loading HTML elements (img/src, CSS url(), @import) embedded in Markdown input. The initial… | |
| Analyzed | Medium (4.3) | 0.29% | — | Rapid7 Insightconnect Compression | 6/25/2026 | 6/29/2026 | Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled by the attacker. | |
| Analyzed | High (8.8) | 1.3% | — | Rapid7 Insightconnect Tcpdump | 6/25/2026 | 6/29/2026 | OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters due to insufficient input sanitization in shell command construction. | |
| Analyzed | Critical (9.8) | 1.2% | — | Rapid7 Insightconnect Traceroute | 6/25/2026 | 6/29/2026 | OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands. | |
| Analyzed | Critical (9.8) | 1.2% | — | Rapid7 Insightconnect Translate | 6/25/2026 | 6/29/2026 | OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction. | |
| Analyzed | High (8.8) | 1.3% | — | Rapid7 Insightconnect Finger | 6/25/2026 | 6/29/2026 | OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters due to insufficient input validation in shell command construction. | |
| Analyzed | Critical (9.8) | 1.2% | — | Rapid7 Insightconnect Ping | 6/25/2026 | 6/29/2026 | OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands. | |
| Analyzed | Critical (9.8) | 1.2% | — | Rapid7 Insightconnect AWK | 6/25/2026 | 6/29/2026 | OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline. |