Vulnerabilities
Summary — last 7 days
New vulnerabilities2,861▲ 226 vs. last week
Critical / high1,331▼ 99 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
36 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | Unscored | — | — | Extutils Typemaps STL String Project Extutils Typemaps STL StringAI | 10/10/2026 | 10/10/2026 | ExtUtils::Typemaps::STL::String versions before 1.06 for Perl T_STD_STRING typemap may read the SV length before stringifying the argument. The typemap uses However, evaluation order for C++ arguments is not specified, and some compilers may produce code that evalutes SvCUR($arg) first. When $arg is not a string (for… | |
| Deferred | High (8.8) | 0.38% | — | String LocatorAI | 10/7/2026 | 10/7/2026 | The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a… | |
| Deferred | High (7.6) | 0.28% | — | StringerAI | 9/28/2026 | 9/30/2026 | Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the Stringer server to send arbitrary HTTP/HTTPS requests to internal networks, localhost services, and cloud metadata endpoints (e.g. AWS… | |
| Awaiting Analysis | Medium (6) | 0.73% | — | Python StringprepAIPython IdnaAI | 8/18/2026 | 10/1/2026 | The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of… | |
| Deferred | High (7.5) | 0.63% | — | String UtilAI | 7/7/2026 | 7/8/2026 | String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex engine retries the… | |
| Deferred | Medium (4.2) | 0.29% | — | Csv-stringifyAIActualbudget ActualAI | 7/7/2026 | 7/9/2026 | Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify with no cast callback and no formula-prefix neutralization. Strings… | |
| Deferred | Critical (9.8) | 0.48% | — | Query-parser-stringAI | 5/7/2026 | 6/17/2026 | NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object. | |
| Deferred | High (8.8) | 0.41% | — | Color-stringAI | 9/15/2025 | 6/17/2026 | color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-string was taken over after a phishing attack. Version 2.1.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect… | |
| Analyzed | High (7) | 0.43% | — | Devrafalko String-math | 6/30/2025 | 6/17/2026 | string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input. | |
| Analyzed | High (7.5) | 0.37% | — | Fractal String\ | 3/28/2025 | 6/17/2026 | String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not… | |
| Deferred | High (7.5) | 0.55% | — | Module-from-stringAI | 2/5/2025 | 6/17/2026 | A prototype pollution in the lib.requireFromString function of module-from-string v3.3.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Analyzed | High (8.8) | 1.1% | — | Instawp String Locator | 1/21/2025 | 6/17/2026 | The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in… | |
| Analyzed | Medium (6.1) | 0.33% | — | Lucasstad Lucas String Replace | 9/13/2024 | 6/17/2026 | The Lucas String Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute… | |
| Analyzed | Medium (6.1) | 0.31% | — | Instawp String Locator | 8/24/2024 | 6/17/2026 | The String locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sql-column' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modified | Critical (9.1) | 0.82% | — | Magiclen Stringbuilder | 7/10/2024 | 6/17/2026 | All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calculation, by calling ToBuffer, ToString, or CharAt on a StringBuilder object with a non-empty string value input. It's possible to return previously allocated memory, for example, by providing negative… | |
| Deferred | Critical (9.8) | 2.4% | — | Ruby StringioAIRubyAI | 5/14/2024 | 6/17/2026 | A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however,… | |
| Modified | High (7.5) | 0.93% | — | String KIT Project String KIT | 1/2/2023 | 6/17/2026 | A vulnerability classified as problematic was found in cronvel string-kit up to 0.12.7. This vulnerability affects the function naturalSort of the file lib/naturalSort.js. The manipulation leads to inefficient regular expression complexity. The attack can be initiated remotely. Upgrading to version 0.12.8 is able to… | |
| Modified | High (7.5) | 1.3% | — | Enumstringvalues Project Enumstringvalues | 12/21/2022 | 6/17/2026 | A vulnerability was found in Brondahl EnumStringValues up to 4.0.0. It has been declared as problematic. This vulnerability affects the function GetStringValuesWithPreferences_Uncache of the file EnumStringValues/EnumExtensions.cs. The manipulation leads to resource consumption. Upgrading to version 4.0.1 is able to… | |
| Modified | Critical (9.8) | 1.1% | — | Democritus D8s-strings | 11/7/2022 | 6/17/2026 | The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-uuids package. The affected version of d8s-htm is 0.1.0. | |
| Modified | Critical (9.8) | 1.7% | — | D8s-strings Project D8s-strings | 9/19/2022 | 6/17/2026 | The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0. | |
| Modified | Critical (9.8) | 1.7% | — | D8s-netstrings Project D8s-netstrings | 9/19/2022 | 6/17/2026 | The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. | |
| Modified | High (8.8) | 1.7% | — | Instawp String Locator | 9/6/2022 | 6/17/2026 | The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path' parameter in versions up to, and including 2.5.0. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an… | |
| Modified | Medium (5.3) | 1.1% | — | Fast String Search Project Fast String Search | 6/17/2022 | 6/17/2026 | All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This allows the attacker to read previously allocated memory. | |
| Modified | High (7.5) | 1.2% | — | Fast String Search Project Fast String Search | 6/17/2022 | 6/17/2026 | All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation. | |
| Modified | Medium (5.4) | 0.77% | — | Jenkins Random String Parameter | 5/17/2022 | 6/17/2026 | Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. |