Vulnerabilities
Summary — last 7 days
New vulnerabilities2,769▼ 305 vs. last week
Critical / high1,294▼ 203 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)207▼ 114 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.8) | 1.9% | — | Nocean Totop Link | 12/13/2021 | 6/17/2026 | The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain. |