Vulnerabilities

Summary — last 7 days

New vulnerabilities3,042▲ 436 vs. last week
Critical / high1,431▲ 190 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)383▲ 168 vs. last week
–

1,416 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.2)——Lastudio Element KITAI10/1/202610/1/2026
Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
DeferredCritical (9.1)0.56%—Ptzoptics Move 4K 12XAIPtzoptics Move 4K 20XAIPtzoptics Move 4K 30XAIPtzoptics Link 4K 12XAI+359/30/20269/30/2026
Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware update mechanism of affected PTZOptics cameras allows an unauthenticated user to install modified firmware on the device…
DeferredMedium (6.4)0.19%—Jegstudio GutenverseAI9/25/20269/25/2026
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
DeferredMedium (6.9)0.65%—Forget-c Jellyfish AI Short Drama StudioAITiangolo FastapiAI9/18/20269/22/2026
A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The…
DeferredHigh (8.8)0.37%—Toolhive CLIAIToolhive StudioAI9/18/20269/24/2026
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while…
DeferredMedium (5.3)0.30%—Whitestudio Easy Form BuilderAI9/18/20269/18/2026
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to create WordPress accounts on a site whose owner has disabled registration.
DeferredHigh (8.8)0.51%—Whitestudio Easy Form BuilderAI9/18/20269/18/2026
The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form types, allowing unauthenticated users to store arbitrary content which is then rendered unescaped in an admin page, leading to Stored XSS.
DeferredMedium (5.4)0.29%—Boxystudio CookedAI9/17/20269/19/2026
Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
DeferredHigh (7.1)0.41%—Coze StudioAI9/16/20269/24/2026
Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata endpoints and internal services reachable only from the backend network, reading…
DeferredHigh (8.7)0.52%—Coze StudioAI9/16/20269/24/2026
Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable table identifiers and execute SQL statements against other workspaces' memory databases to read, insert, or delete data.
DeferredMedium (6.4)0.21%—Ashstonestudios Advanced PopupsAI9/16/20269/16/2026
The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to…
DeferredMedium (4.4)0.19%—Outerbase StudioAIPostgresqlAIMysqlAISqliteAI9/15/20269/30/2026
Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangerouslySetInnerHTML, allowing injected markup with script-capable event handlers to…
DeferredHigh (8.8)0.51%—Jegstudio Gutenverse NewsAI9/11/20269/11/2026
The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in…
DeferredHigh (8.6)0.53%—Studiowombat Advanced Product Fields Extended FOR WoocommerceAI9/10/20269/11/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6.
AnalyzedHigh (7.4)0.92%—Microsoft Visual Studio Code9/8/20269/10/2026
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
AnalyzedHigh (7.5)0.87%—Microsoft Visual Studio Code9/8/20269/15/2026
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
AnalyzedMedium (5.9)0.62%—Microsoft Visual Studio Code9/8/20269/23/2026
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
AnalyzedHigh (8.2)0.54%—Microsoft Visual Studio Code9/8/20269/11/2026
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalyzedHigh (8.2)0.54%—Microsoft Visual Studio Code9/8/20269/11/2026
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalyzedMedium (6.5)0.76%—Microsoft Visual Studio Code9/8/20269/11/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
AnalyzedCritical (9.6)0.82%—Microsoft Visual Studio Code9/8/20269/11/2026
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalyzedHigh (8.2)0.51%—Microsoft Visual Studio Code9/8/20269/11/2026
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalyzedHigh (8.2)0.54%—Microsoft Visual Studio Code9/8/20269/11/2026
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalyzedHigh (8.8)0.76%—Microsoft Visual Studio Code9/8/20269/11/2026
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
AnalyzedHigh (7.4)1.0%—Microsoft Visual Studio Code9/8/20269/11/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.