Vulnerabilities

Summary — last 7 days

New vulnerabilities2,769▼ 305 vs. last week
Critical / high1,294▼ 203 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)207▼ 114 vs. last week
–

1 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedCritical (9.8)1.9%—Nocean Totop Link12/13/20216/17/2026
The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain.
Orbitaley — Vulnerabilities