Vulnerabilities
Summary — last 7 days
New vulnerabilities2,715▼ 529 vs. last week
Critical / high1,290▼ 220 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | High (7.5) | 95% | ⚠ Active exploitation💥 Exploit | Zkoss ZK Framework | 8/26/2022 | 6/17/2026 | ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader. | |
| Modified | Medium (4.3) | 1.2% | — | Zkoss ZK Framework | 11/20/2013 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in ZK Framework before 5.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |