Vulnerabilities
Summary — last 7 days
New vulnerabilities3,072▲ 552 vs. last week
Critical / high1,458▲ 273 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)383▲ 176 vs. last week
379 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (8.6) | 0.43% | — | Dani-garcia VaultwardenAI | 9/22/2026 | 9/24/2026 | Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status… | |
| Deferred | Medium (6.9) | 0.19% | — | McpvaultAIObsidianAI | 9/15/2026 | 9/30/2026 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, PathFilter in src/pathfilter.ts uses root-anchored deny-list patterns, so nested .git, .obsidian, and node_modules path segments do not match the restriction and pass both isAllowed() and… | |
| Deferred | High (8.4) | 0.20% | — | McpvaultAI | 9/15/2026 | 9/30/2026 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without canonicalizing filesystem-equivalent segment names. On case-insensitive macOS and… | |
| Deferred | High (7.1) | 0.25% | — | Gallery Private Photo VaultAI | 9/14/2026 | 9/18/2026 | Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage. | |
| Deferred | Medium (5.8) | 0.16% | — | Hashicorp Vault-jsAI | 9/14/2026 | 9/30/2026 | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosError.config and the equivalent response configuration. These objects can contain… | |
| Analyzed | High (7.7) | 0.58% | — | Commvault | 9/8/2026 | 9/11/2026 | Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. | |
| Analyzed | High (8.7) | 0.30% | — | Commvault | 9/8/2026 | 9/9/2026 | CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server. | |
| Analyzed | High (8.3) | 0.56% | — | Commvault | 9/8/2026 | 9/9/2026 | CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. | |
| Analyzed | High (8.7) | 0.50% | — | Commvault | 9/8/2026 | 9/9/2026 | CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe. | |
| Analyzed | High (8.7) | 0.46% | — | Commvault | 9/8/2026 | 9/9/2026 | CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. | |
| Analyzed | High (8.7) | 0.46% | — | Commvault | 9/8/2026 | 9/9/2026 | CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe. | |
| Analyzed | High (8.8) | 0.47% | — | Commvault | 9/8/2026 | 9/11/2026 | Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server. | |
| Analyzed | High (8.8) | 0.47% | — | Commvault | 9/8/2026 | 9/11/2026 | Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics Server. | |
| Analyzed | High (7.3) | 0.32% | — | Commvault | 9/8/2026 | 9/11/2026 | Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor. | |
| Analyzed | High (8.5) | 0.18% | — | Commvault | 9/8/2026 | 9/11/2026 | DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store. | |
| Analyzed | Critical (9.3) | 0.61% | — | Commvault | 9/8/2026 | 9/11/2026 | Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center. | |
| Deferred | High (8.3) | 0.41% | — | Helicone VaultmanagerAI | 9/3/2026 | 9/24/2026 | Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can retrieve decrypted upstream provider… | |
| Deferred | High (7.9) | 0.15% | — | Synergis SoftwireAIStreamvault Sv-100eAIStreamvault Sv-300eAI | 8/28/2026 | 9/9/2026 | Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers. | |
| Deferred | High (8.1) | 0.23% | — | Blogvault Backup AND StagingAIMalcare Wordpress Security PluginAITHE WP Remote WP RemoteAI | 8/26/2026 | 8/26/2026 | The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service,… | |
| Awaiting Analysis | Medium (6.8) | 0.28% | — | Hashicorp VaultAI | 8/24/2026 | 8/28/2026 | A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced identity value may include slash ({{/}})… | |
| Awaiting Analysis | Critical (9.6) | 0.35% | — | Redhat Ansible Automation PlatformAIHashicorp VaultAI | 8/18/2026 | 9/24/2026 | A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role… | |
| Deferred | Low (1.3) | 0.39% | — | Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI | 8/17/2026 | 8/20/2026 | A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level… | |
| Awaiting Analysis | Critical (9.6) | 0.47% | — | Hashicorp Vault Secrets OperatorAI | 8/13/2026 | 8/28/2026 | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a… | |
| Analyzed | High (8.8) | 0.39% | — | Commvault | 8/11/2026 | 9/9/2026 | A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center. | |
| Analyzed | Critical (9.2) | 0.63% | — | Commvault | 8/11/2026 | 9/11/2026 | CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X. |