Vulnerabilities
Summary — last 7 days
New vulnerabilities2,716▼ 25 vs. last week
Critical / high1,269▼ 244 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
10 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Undergoing Analysis | Medium (5.3) | 0.62% | 💥 PoC | Weibo Rill-flow | 5/18/2025 | 6/17/2026 | A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical. Affected is an unknown function of the component Management Console. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Modified | High (7.5) | 0.80% | 💥 PoC | Weibo Android Software Development KIT | 4/5/2022 | 6/17/2026 | An intent redirection issue was doscovered in Sina Weibo Android SDK 4.2.7 (com.sina.weibo.sdk.share.WbShareTransActivity), any unexported Activities could be started by the com.sina.weibo.sdk.share.WbShareTransActivity. | |
| Modified | Critical (9.8) | 2.4% | — | Omniauth-weibo-oauth2 Project Omniauth-weibo-oauth2 | 2/7/2020 | 6/17/2026 | The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected. | |
| Modified | Medium (5.5) | 0.33% | — | Jenkins Weibo | 12/17/2019 | 6/17/2026 | Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modified | Medium (5.4) | 0.27% | — | Weibo Project Weibo | 9/30/2014 | 6/17/2026 | The weibo (aka magic.weibo) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modified | High (10) | 1.4% | — | Goforandroid GO Weibowidget | 3/7/2012 | 6/16/2026 | Unspecified vulnerability in the GO WeiboWidget (com.gau.go.launcherex.gowidget.weibowidget) application 2.4 for Android has unknown impact and attack vectors. | |
| Modified | High (10) | 1.4% | — | Goforandroid GO Qqweibowidget | 3/7/2012 | 6/16/2026 | Unspecified vulnerability in the GO QQWeiboWidget (com.gau.go.launcherex.gowidget.qqweibowidget) application 1.2 for Android has unknown impact and attack vectors. | |
| Modified | High (10) | 1.4% | — | Icekirin DI Long Weibo | 3/7/2012 | 6/16/2026 | Unspecified vulnerability in the Di Long Weibo (com.icekirin.weibos) application 1.9.9 for Android has unknown impact and attack vectors. | |
| Modified | High (10) | 1.4% | — | Netease Weibohd | 3/7/2012 | 6/16/2026 | Unspecified vulnerability in the NetEase WeiboHD (com.netease.wbhd) application 1.0.0 for Android has unknown impact and attack vectors. | |
| Modified | High (10) | 1.4% | — | Neteaseweibo | 3/7/2012 | 6/16/2026 | Unspecified vulnerability in the NetEaseWeibo (com.netease.wb) application 1.2.1 and 1.2.2 for Android has unknown impact and attack vectors. |