Vulnerabilities
Summary — last 7 days
New vulnerabilities2,771▲ 6 vs. last week
Critical / high1,285▼ 246 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)242▲ 224 vs. last week
35 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.5) | 1.5% | — | THE Address Book | 12/31/2006 | 6/16/2026 | export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote attackers to obtain sensitive information. | |
| Modified | High (7.5) | 1.5% | — | THE Address Book | 12/31/2006 | 6/16/2026 | register.php in The Address Book 1.04e allows remote attackers to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "confirm". | |
| Modified | Medium (6.8) | 1.6% | — | THE Address Book | 12/31/2006 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email, (2) websites, and (3) groupAddName parameters in (a) save.php; the (4) errorMsg parameter in (b) index.php; and the (5) goTo and (6) search… | |
| Modified | Medium (6.8) | 1.4% | — | THE Address Book | 12/31/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows remote attackers to inject arbitrary web script or HTML by uploading the HTML file with a GIF or JPG extension, which is rendered by Internet Explorer. | |
| Modified | Medium (5) | 1.3% | — | THE Address Book | 12/31/2006 | 6/16/2026 | Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts. | |
| Modified | High (7.5) | 2.2% | — | THE Address Book | 12/31/2006 | 6/16/2026 | Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) newuserEmail parameters in (a) user.php; the… | |
| Modified | Medium (5) | 6.4% | 💥 Exploit | EFS Software Easy Address Book | 11/4/2006 | 6/16/2026 | Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of an HTTP GET request, which accesses the alternate data stream. | |
| Modified | Medium (5.1) | 2.2% | 💥 Exploit | EFS Software Easy Address Book WEB Server | 9/9/2006 | 6/16/2026 | Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string specifiers in the query string. | |
| Modified | High (7.5) | 1.5% | — | THE Address BookTHE Address Book Reloaded | 8/10/2006 | 6/16/2026 | Multiple SQL injection vulnerabilities in the authentication process in katzlbt (a) The Address Book 1.04e and earlier and (b) The Address Book Reloaded before 2.0-rc4 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. NOTE: portions of these details are obtained… | |
| Modified | Medium (4.3) | 1.3% | — | Handy Address Book Server | 9/22/2005 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in Handy Address Book Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the SEARCHTEXT parameter in a demos URL. |