Vulnerabilities

Summary — last 7 days

New vulnerabilities2,567▼ 300 vs. last week
Critical / high1,352▲ 101 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
–

166 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.3)0.23%—Gitoxide Gix-transportAI9/15/20269/23/2026
gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into daemon requests and logs.
DeferredMedium (6)0.38%—Qbee TransportAI9/15/20269/30/2026
qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A crafted tar archive can use a symlink chain to write or overwrite files one…
DeferredMedium (5.3)0.52%—Quic-go Webtransport-goAI9/14/20269/30/2026
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, retaining the complete declared capsule body in memory. A malicious peer can send…
DeferredHigh (8.7)0.41%—Gitoxide Gix-urlAIGitoxide Gix-transportAI8/28/20268/28/2026
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect identity guard (can_reuse_identity) compares the wrong host and fails open. An attacker…
AnalyzedHigh (7.6)0.25%—Oracle Transportation Execution8/18/20268/28/2026
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution.…
Awaiting AnalysisCritical (9.4)0.50%—Axway SecuretransportAI7/29/20267/30/2026
A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker with admin privileges to inject arbitrary Java code expressions, which are executed server-side when the template is…
DeferredMedium (6.5)0.17%—WOO Transport CompanyAI7/23/20267/23/2026
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
AnalyzedHigh (7.6)0.32%—Oracle Transportation Management7/21/20268/6/2026
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: CSV Management). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful…
AnalyzedHigh (8.8)0.43%—Oracle Transportation Management7/21/20268/6/2026
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of…
AnalyzedMedium (4.3)0.27%—Oracle Transportation Management7/21/20268/3/2026
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful…
AnalyzedMedium (6.5)0.41%—Oracle Transportation Management7/21/20268/3/2026
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Integration). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful…
Awaiting AnalysisHigh (7.6)0.56%—SAP Change AND Transport System Attach ToolAI7/14/20267/14/2026
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim…
AnalyzedMedium (5.3)0.39%—Quic-go Webtransport-go2/12/20266/17/2026
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Closed streams were not removed from an internal session map, preventing garbage collection of their resources. This…
AnalyzedHigh (7.5)0.44%—Quic-go Webtransport-go2/12/20266/17/2026
webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by preventing or indefinitely delaying WebTransport session closure. A malicious peer can withhold QUIC flow control credit on the CONNECT stream, blocking transmission of…
AnalyzedHigh (7.5)0.44%—Quic-go Webtransport-go2/12/20266/17/2026
webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive memory consumption in webtransport-go's session implementation by sending a WT_CLOSE_SESSION capsule containing an excessively large Application Error Message. The implementation does not enforce the…
DeferredMedium (4.1)0.18%—Gix-transportAI7/28/20256/17/2026
The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit.
DeferredHigh (7.5)0.44%—Karnataka State Road Transport Corporation Ksrtc AwatarAI3/6/20256/17/2026
Incorrect access control in the KSRTC AWATAR app of Karnataka State Road Transport Corporation v1.3.0 allows to view sensitive information such as usernames and passwords.
DeferredMedium (6.1)0.20%—TransportersAI1/7/20256/17/2026
The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a…
ModifiedMedium (5)0.35%—SaptmuiSAP Transportation Management7/9/20246/17/2026
SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal information about that service. The information…
DeferredMedium (6.4)0.51%—Gitoxide Gix-transportAI4/26/20246/17/2026
gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The possibilities are syntactically limited, but if a malicious clone URL is used by…
ModifiedMedium (6.1)0.46%—Sesami Cash Point & Transport Optimizer12/29/20236/17/2026
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field.
ModifiedHigh (7.5)0.36%—Sesami Cash Point & Transport Optimizer12/29/20236/17/2026
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.
ModifiedHigh (7.5)0.58%—Sesami Cash Point & Transport Optimizer12/29/20236/17/2026
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the User Profile field.
ModifiedMedium (6.1)0.46%—Sesami Cash Point & Transport Optimizer12/29/20236/17/2026
Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container.
ModifiedMedium (5.3)0.38%—Sesami Cash Point & Transport Optimizer12/29/20236/17/2026
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.