Vulnerabilities

Summary — last 7 days

New vulnerabilities2,686▼ 84 vs. last week
Critical / high1,444▲ 301 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredCritical (9.1)0.21%—Amazon Simple Notification ServiceAIUseplunk PlunkAI5/8/20266/17/2026
Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification payloads from unauthenticated requests without verifying the SNS signature, certificate, or topic ARN, meaning anyone can forge a valid-looking webhook request. This allows…
DeferredMedium (6.4)0.24%—Simple NotificationAI3/5/20256/17/2026
The Simple Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages…
DeferredMedium (6.5)0.36%—Appsbd Simple NotificationAI12/13/20246/17/2026
Missing Authorization vulnerability in appsbd Simple Notification simple-notification allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Notification: from n/a through <= 1.3.