Vulnerabilities
Summary — last 7 days
New vulnerabilities2,737▼ 484 vs. last week
Critical / high1,302▼ 187 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)227▼ 275 vs. last week
52 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (4.3) | 1.5% | 💥 Exploit | Alexandre Amaral Xoops Celepar | 3/15/2010 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in the quiz module for XOOPS Celepar allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to cadastro_usuario.php. | |
| Modified | Medium (4.3) | 1.5% | 💥 Exploit | Alexandre Amaral Xoops Celepar | 3/15/2010 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to inject arbitrary web script or HTML via (1) the cod_categoria parameter to categoria.php, (2) the opcao parameter to index.php, and the PATH_INFO to (3) categoria.php and (4) index.php. | |
| Modified | High (7.5) | 1.7% | 💥 Exploit | Alexandre Amaral Xoops Celepar | 3/15/2010 | 6/16/2026 | Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php. | |
| Modified | Low (3.5) | 2.8% | 💥 Exploit | Alexander Hass Sections Module | 12/28/2009 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in the Sections module 5.x before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote authenticated users with "administer sections" privileges to inject arbitrary web script or HTML via a section name (aka the Name field). | |
| Modified | Medium (6.5) | 2.0% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 12/24/2009 | 6/16/2026 | Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the blog_language1 parameter. | |
| Modified | Medium (6) | 0.82% | 💥 Exploit | Ricardo Alexandre DE Oliveira Staudt Yogurt | 6/12/2009 | 6/16/2026 | SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authenticated users to execute arbitrary SQL commands via the original parameter. | |
| Modified | Medium (4.3) | 1.5% | 💥 Exploit | Ricardo Alexandre DE Oliveira Staudt Yogurt | 6/12/2009 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in index.php in Yogurt 0.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modified | Medium (5) | 1.2% | 💥 Exploit | Vlad Alexa Mancini Phpfootball | 2/23/2009 | 6/16/2026 | filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance… | |
| Modified | Medium (4.3) | 1.5% | 💥 Exploit | Vlad Alexa Mancini Phpfootball | 2/23/2009 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the user parameter to login.php or (2) the dbfield parameter to filter.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modified | High (7.5) | 0.95% | 💥 Exploit | Vlad Alexa Mancini Phpfootball | 2/23/2009 | 6/16/2026 | SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modified | Medium (4.3) | 1.3% | — | Alexander Palmo Simple PHP Blog | 9/24/2007 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog (SPHPBlog) before 0.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via certain user_colors array parameters to certain user_style.php files under themes/, as demonstrated by the… | |
| Modified | High (7.5) | 3.0% | — | Alexander Palmo Simple PHP Blog | 9/24/2007 | 6/16/2026 | Incomplete blacklist vulnerability in upload_img_cgi.php in Simple PHP Blog before 0.5.1 allows remote attackers to upload dangerous files and execute arbitrary code, as demonstrated by a filename ending in .php. or a .htaccess file, a different vector than CVE-2005-2733. NOTE: the vulnerability was also present in a… | |
| Modified | Medium (6.8) | 3.2% | — | Alexander V. Lukyanov Lftp | 4/27/2007 | 6/16/2026 | mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which… | |
| Modified | Medium (5) | 3.1% | 💥 Exploit | Vlad Alexa Mancini Phpfootball | 1/31/2007 | 6/16/2026 | show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter. | |
| Modified | High (7.5) | 3.6% | 💥 Exploit | Jason Alexander Phnntp | 8/14/2006 | 6/16/2026 | PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter. | |
| Modified | High (7.5) | 9.7% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 3/15/2006 | 6/16/2026 | Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache… | |
| Modified | Medium (4.3) | 2.2% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 11/3/2005 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4)… | |
| Modified | Medium (5) | 5.6% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 9/2/2005 | 6/16/2026 | comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter. | |
| Modified | High (7.5) | 51% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 8/30/2005 | 6/16/2026 | upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code. | |
| Modified | Low (2.6) | 1.4% | — | Alexander Clauss Icab | 7/13/2005 | 6/16/2026 | iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability." | |
| Modified | Medium (5) | 4.1% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 7/11/2005 | 6/16/2026 | SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack. | |
| Modified | Medium (5) | 1.7% | — | Alexander Palmo Simple PHP Blog | 5/2/2005 | 6/16/2026 | Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter. | |
| Modified | Medium (5) | 1.3% | — | Alexander Palmo Simple PHP Blog | 5/2/2005 | 6/16/2026 | Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message. | |
| Modified | Medium (4.6) | 0.44% | — | Alexander Siegel Golddig | 5/2/2005 | 6/16/2026 | Multiple buffer overflows in golddig 2.0 and earlier allow local users to execute arbitrary code via (1) a long map name command line argument or (2) a long username as recorded in the USER environment variable. | |
| Modified | Medium (4.3) | 1.7% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 5/2/2005 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. |