Vulnerabilities

Summary — last 7 days

New vulnerabilities2,851▼ 221 vs. last week
Critical / high1,332▼ 167 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)222▼ 99 vs. last week
–

143 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (8.8)1.4%—Simbahosting Two-factor-authentication12/19/20186/17/2026
Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation.
ModifiedHigh (7.8)0.35%—Ehcp Easy Hosting Control Panel5/11/20186/17/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt.
ModifiedHigh (7.8)0.46%—Ehcp Easy Hosting Control Panel5/11/20186/17/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.
ModifiedHigh (7.8)0.41%—Ehcp Easy Hosting Control Panel5/11/20186/17/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the current password.
ModifiedHigh (8.8)10.0%—Ehcp Easy Hosting Control Panel5/11/20186/17/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
ModifiedMedium (6.1)1.0%—Ehcp Easy Hosting Control Panel5/11/20186/17/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.
ModifiedMedium (6.1)38%—Ehcp Easy Hosting Control Panel5/11/20186/17/2026
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.
ModifiedHigh (8.8)0.77%—Hosting Project Hosting2/21/20186/17/2026
A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any files in any hosting account.
ModifiedMedium (6.1)1.5%💥 ExploitReservo Image Hosting1/24/20186/17/2026
Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.
ModifiedMedium (6.1)2.1%💥 ExploitFoxsash Imghosting1/15/20186/17/2026
FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the search parameter to the default URI. Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an…
ModifiedMedium (6.1)0.66%—Fenix Hosting Fenix-open-source3/5/20176/17/2026
FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic parameter).
ModifiedHigh (7.5)1.9%—Redmine GIT Hosting Plugin12/28/20146/16/2026
git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exists function.
ModifiedMedium (5.4)0.27%—Etghosting ETG Hosting10/19/20146/17/2026
The ETG Hosting (aka com.etg.web.hosting) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModifiedMedium (4.3)1.2%—Ikiwiki Hosting Project Ikiwiki Hosting2/25/20146/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in the site creation interface in ikiwiki-hosting before 0.20131025 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModifiedHigh (7.5)1.1%💥 ExploitYabsoft Advanced Image Hosting Script11/26/20126/16/2026
SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to execute arbitrary SQL commands via the gal parameter.
ModifiedMedium (4.3)1.1%—Clixint Image Hosting Script DPI2/2/20126/16/2026
Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter.
ModifiedMedium (4.3)1.5%💥 ExploitCodefuture CF Image Hosting Script11/29/20116/16/2026
Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this was originally reported as a file disclosure vulnerability, but this is…
ModifiedMedium (5)1.2%—Thehostingtool9/24/20116/16/2026
TheHostingTool (THT) 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/pear/Mail/smtp.php and certain other files.
ModifiedHigh (7.5)6.4%💥 ExploitScripteen Free Image Hosting Script8/25/20106/16/2026
admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting the cookgid cookie value to 1, a different vector than CVE-2008-3211.
ModifiedMedium (6.8)0.94%💥 ExploitScriptsez Mini Hosting Panel4/27/20106/16/2026
Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for requests that alter administrative settings via a cp action.
ModifiedMedium (4.3)1.4%💥 ExploitYabsoft Advanced Image Hosting Script12/10/20096/16/2026
Cross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote attackers to inject arbitrary web script or HTML via the text parameter.
ModifiedMedium (4.3)1.1%—Clixint Image Hosting Script DPI12/10/20096/16/2026
Cross-site scripting (XSS) vulnerability in images.php in Image Hosting Script DPI 1.1 Final (1.1F) allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: some of these details are obtained from third party information.
ModifiedMedium (4.3)1.2%💥 ExploitYabsoft Mega File Hosting Script10/9/20096/16/2026
Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the moudi parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModifiedHigh (7.5)1.1%💥 ExploitScripteen Free Image Hosting Script8/20/20096/16/2026
Multiple SQL injection vulnerabilities in header.php in Scripteen Free Image Hosting Script 2.3 allow remote attackers to execute arbitrary SQL commands via a (1) cookid or (2) cookgid cookie.
ModifiedHigh (7.5)0.97%💥 ExploitWebhost-panel Bankoi Webhosting Control Panel8/12/20096/16/2026
Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.
Orbitaley — Vulnerabilities