Vulnerabilities
Summary — last 7 days
New vulnerabilities2,567▼ 300 vs. last week
Critical / high1,352▲ 101 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
166 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.23% | — | Gitoxide Gix-transportAI | 9/15/2026 | 9/23/2026 | gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs. | |
| Deferred | Medium (6) | 0.38% | — | Qbee TransportAI | 9/15/2026 | 9/30/2026 | qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A crafted tar archive can use a symlink chain to write or overwrite files one… | |
| Deferred | Medium (5.3) | 0.52% | — | Quic-go Webtransport-goAI | 9/14/2026 | 9/30/2026 | webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, retaining the complete declared capsule body in memory. A malicious peer can send… | |
| Deferred | High (8.7) | 0.41% | — | Gitoxide Gix-urlAIGitoxide Gix-transportAI | 8/28/2026 | 8/28/2026 | gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect identity guard (can_reuse_identity) compares the wrong host and fails open. An attacker… | |
| Analyzed | High (7.6) | 0.25% | — | Oracle Transportation Execution | 8/18/2026 | 8/28/2026 | Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution.… | |
| Awaiting Analysis | Critical (9.4) | 0.50% | — | Axway SecuretransportAI | 7/29/2026 | 7/30/2026 | A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker with admin privileges to inject arbitrary Java code expressions, which are executed server-side when the template is… | |
| Deferred | Medium (6.5) | 0.17% | — | WOO Transport CompanyAI | 7/23/2026 | 7/23/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. | |
| Analyzed | High (7.6) | 0.32% | — | Oracle Transportation Management | 7/21/2026 | 8/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: CSV Management). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful… | |
| Analyzed | High (8.8) | 0.43% | — | Oracle Transportation Management | 7/21/2026 | 8/6/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of… | |
| Analyzed | Medium (4.3) | 0.27% | — | Oracle Transportation Management | 7/21/2026 | 8/3/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful… | |
| Analyzed | Medium (6.5) | 0.41% | — | Oracle Transportation Management | 7/21/2026 | 8/3/2026 | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Integration). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful… | |
| Awaiting Analysis | High (7.6) | 0.56% | — | SAP Change AND Transport System Attach ToolAI | 7/14/2026 | 7/14/2026 | SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim… | |
| Analyzed | Medium (5.3) | 0.39% | — | Quic-go Webtransport-go | 2/12/2026 | 6/17/2026 | webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Closed streams were not removed from an internal session map, preventing garbage collection of their resources. This… | |
| Analyzed | High (7.5) | 0.44% | — | Quic-go Webtransport-go | 2/12/2026 | 6/17/2026 | webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by preventing or indefinitely delaying WebTransport session closure. A malicious peer can withhold QUIC flow control credit on the CONNECT stream, blocking transmission of… | |
| Analyzed | High (7.5) | 0.44% | — | Quic-go Webtransport-go | 2/12/2026 | 6/17/2026 | webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive memory consumption in webtransport-go's session implementation by sending a WT_CLOSE_SESSION capsule containing an excessively large Application Error Message. The implementation does not enforce the… | |
| Deferred | Medium (4.1) | 0.18% | — | Gix-transportAI | 7/28/2025 | 6/17/2026 | The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit. | |
| Deferred | High (7.5) | 0.44% | — | Karnataka State Road Transport Corporation Ksrtc AwatarAI | 3/6/2025 | 6/17/2026 | Incorrect access control in the KSRTC AWATAR app of Karnataka State Road Transport Corporation v1.3.0 allows to view sensitive information such as usernames and passwords. | |
| Deferred | Medium (6.1) | 0.20% | — | TransportersAI | 1/7/2025 | 6/17/2026 | The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a… | |
| Modified | Medium (5) | 0.35% | — | SaptmuiSAP Transportation Management | 7/9/2024 | 6/17/2026 | SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal information about that service. The information… | |
| Deferred | Medium (6.4) | 0.51% | — | Gitoxide Gix-transportAI | 4/26/2024 | 6/17/2026 | gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The possibilities are syntactically limited, but if a malicious clone URL is used by… | |
| Modified | Medium (6.1) | 0.46% | — | Sesami Cash Point & Transport Optimizer | 12/29/2023 | 6/17/2026 | Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field. | |
| Modified | High (7.5) | 0.36% | — | Sesami Cash Point & Transport Optimizer | 12/29/2023 | 6/17/2026 | An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature. | |
| Modified | High (7.5) | 0.58% | — | Sesami Cash Point & Transport Optimizer | 12/29/2023 | 6/17/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field. | |
| Modified | Medium (6.1) | 0.46% | — | Sesami Cash Point & Transport Optimizer | 12/29/2023 | 6/17/2026 | Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container. | |
| Modified | Medium (5.3) | 0.38% | — | Sesami Cash Point & Transport Optimizer | 12/29/2023 | 6/17/2026 | CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field. |