60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running …
A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and …
A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, …
A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's …
A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after …
A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X.509 …
A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is copied in clear text …
A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonymous response, exposing the …
A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. …
An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to …
Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH …
Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.
Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.
Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.
Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.
Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.
Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.
Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.
Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.
Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.
Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.
Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.
Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.
Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.
Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a …
Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions.
Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a …
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HISTORY_IGNORE configuration …
StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod. Tenant superuser can confirm …
HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse …
/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user. The superuser/auditor gate only covers project_base_dir/project_local_paths/custom_virtualenvs, …
JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for any authenticated user. The view uses raw get_object_or_404(Job, pk) without DRF object-level permission check. …
URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403→404 shim only rewrites 403 responses, leaving the pk=0 miss path with a different 404 …
GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference …
BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.
BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.
Free website and port scanning — find vulnerabilities before attackers do.