Vulnerabilities

Summary — last 7 days

New vulnerabilities2,737▼ 484 vs. last week
Critical / high1,302▼ 187 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)227▼ 275 vs. last week
–

52 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (4.3)1.5%💥 ExploitAlexandre Amaral Xoops Celepar3/15/20106/16/2026
Cross-site scripting (XSS) vulnerability in the quiz module for XOOPS Celepar allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to cadastro_usuario.php.
ModifiedMedium (4.3)1.5%💥 ExploitAlexandre Amaral Xoops Celepar3/15/20106/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to inject arbitrary web script or HTML via (1) the cod_categoria parameter to categoria.php, (2) the opcao parameter to index.php, and the PATH_INFO to (3) categoria.php and (4) index.php.
ModifiedHigh (7.5)1.7%💥 ExploitAlexandre Amaral Xoops Celepar3/15/20106/16/2026
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php.
ModifiedLow (3.5)2.8%💥 ExploitAlexander Hass Sections Module12/28/20096/16/2026
Cross-site scripting (XSS) vulnerability in the Sections module 5.x before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote authenticated users with "administer sections" privileges to inject arbitrary web script or HTML via a section name (aka the Name field).
ModifiedMedium (6.5)2.0%💥 ExploitAlexander Palmo Simple PHP Blog12/24/20096/16/2026
Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the blog_language1 parameter.
ModifiedMedium (6)0.82%💥 ExploitRicardo Alexandre DE Oliveira Staudt Yogurt6/12/20096/16/2026
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authenticated users to execute arbitrary SQL commands via the original parameter.
ModifiedMedium (4.3)1.5%💥 ExploitRicardo Alexandre DE Oliveira Staudt Yogurt6/12/20096/16/2026
Cross-site scripting (XSS) vulnerability in index.php in Yogurt 0.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
ModifiedMedium (5)1.2%💥 ExploitVlad Alexa Mancini Phpfootball2/23/20096/16/2026
filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance…
ModifiedMedium (4.3)1.5%💥 ExploitVlad Alexa Mancini Phpfootball2/23/20096/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the user parameter to login.php or (2) the dbfield parameter to filter.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModifiedHigh (7.5)0.95%💥 ExploitVlad Alexa Mancini Phpfootball2/23/20096/16/2026
SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModifiedMedium (4.3)1.3%—Alexander Palmo Simple PHP Blog9/24/20076/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog (SPHPBlog) before 0.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via certain user_colors array parameters to certain user_style.php files under themes/, as demonstrated by the…
ModifiedHigh (7.5)3.0%—Alexander Palmo Simple PHP Blog9/24/20076/16/2026
Incomplete blacklist vulnerability in upload_img_cgi.php in Simple PHP Blog before 0.5.1 allows remote attackers to upload dangerous files and execute arbitrary code, as demonstrated by a filename ending in .php. or a .htaccess file, a different vector than CVE-2005-2733. NOTE: the vulnerability was also present in a…
ModifiedMedium (6.8)3.2%—Alexander V. Lukyanov Lftp4/27/20076/16/2026
mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which…
ModifiedMedium (5)3.1%💥 ExploitVlad Alexa Mancini Phpfootball1/31/20076/16/2026
show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter.
ModifiedHigh (7.5)3.6%💥 ExploitJason Alexander Phnntp8/14/20066/16/2026
PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.
ModifiedHigh (7.5)9.7%💥 ExploitAlexander Palmo Simple PHP Blog3/15/20066/16/2026
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache…
ModifiedMedium (4.3)2.2%💥 ExploitAlexander Palmo Simple PHP Blog11/3/20056/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4)…
ModifiedMedium (5)5.6%💥 ExploitAlexander Palmo Simple PHP Blog9/2/20056/16/2026
comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.
ModifiedHigh (7.5)51%💥 ExploitAlexander Palmo Simple PHP Blog8/30/20056/16/2026
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.
ModifiedLow (2.6)1.4%—Alexander Clauss Icab7/13/20056/16/2026
iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."
ModifiedMedium (5)4.1%💥 ExploitAlexander Palmo Simple PHP Blog7/11/20056/16/2026
SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.
ModifiedMedium (5)1.7%—Alexander Palmo Simple PHP Blog5/2/20056/16/2026
Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.
ModifiedMedium (5)1.3%—Alexander Palmo Simple PHP Blog5/2/20056/16/2026
Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message.
ModifiedMedium (4.6)0.44%—Alexander Siegel Golddig5/2/20056/16/2026
Multiple buffer overflows in golddig 2.0 and earlier allow local users to execute arbitrary code via (1) a long map name command line argument or (2) a long username as recorded in the USER environment variable.
ModifiedMedium (4.3)1.7%💥 ExploitAlexander Palmo Simple PHP Blog5/2/20056/16/2026
Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.