Vulnerabilities
Summary — last 7 days
New vulnerabilities2,851▼ 221 vs. last week
Critical / high1,332▼ 167 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)222▼ 99 vs. last week
143 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (8.8) | 1.4% | — | Simbahosting Two-factor-authentication | 12/19/2018 | 6/17/2026 | Cross Site Request Forgery (CSRF) in the two-factor-authentication plugin before 1.3.13 for WordPress allows remote attackers to disable 2FA via the tfa_enable_tfa parameter due to missing nonce validation. | |
| Modified | High (7.8) | 0.35% | — | Ehcp Easy Hosting Control Panel | 5/11/2018 | 6/17/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt. | |
| Modified | High (7.8) | 0.46% | — | Ehcp Easy Hosting Control Panel | 5/11/2018 | 6/17/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage. | |
| Modified | High (7.8) | 0.41% | — | Ehcp Easy Hosting Control Panel | 5/11/2018 | 6/17/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the current password. | |
| Modified | High (8.8) | 10.0% | — | Ehcp Easy Hosting Control Panel | 5/11/2018 | 6/17/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection. | |
| Modified | Medium (6.1) | 1.0% | — | Ehcp Easy Hosting Control Panel | 5/11/2018 | 6/17/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie. | |
| Modified | Medium (6.1) | 38% | — | Ehcp Easy Hosting Control Panel | 5/11/2018 | 6/17/2026 | Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account. | |
| Modified | High (8.8) | 0.77% | — | Hosting Project Hosting | 2/21/2018 | 6/17/2026 | A CSRF issue was found in var/www/html/files.php in DanWin hosting through 2018-02-11 that allows arbitrary remote users to add/delete/modify any files in any hosting account. | |
| Modified | Medium (6.1) | 1.5% | 💥 Exploit | Reservo Image Hosting | 1/24/2018 | 6/17/2026 | Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed. | |
| Modified | Medium (6.1) | 2.1% | 💥 Exploit | Foxsash Imghosting | 1/15/2018 | 6/17/2026 | FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the search parameter to the default URI. Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an… | |
| Modified | Medium (6.1) | 0.66% | — | Fenix Hosting Fenix-open-source | 3/5/2017 | 6/17/2026 | FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic parameter). | |
| Modified | High (7.5) | 1.9% | — | Redmine GIT Hosting Plugin | 12/28/2014 | 6/16/2026 | git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exists function. | |
| Modified | Medium (5.4) | 0.27% | — | Etghosting ETG Hosting | 10/19/2014 | 6/17/2026 | The ETG Hosting (aka com.etg.web.hosting) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modified | Medium (4.3) | 1.2% | — | Ikiwiki Hosting Project Ikiwiki Hosting | 2/25/2014 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the site creation interface in ikiwiki-hosting before 0.20131025 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modified | High (7.5) | 1.1% | 💥 Exploit | Yabsoft Advanced Image Hosting Script | 11/26/2012 | 6/16/2026 | SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to execute arbitrary SQL commands via the gal parameter. | |
| Modified | Medium (4.3) | 1.1% | — | Clixint Image Hosting Script DPI | 2/2/2012 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter. | |
| Modified | Medium (4.3) | 1.5% | 💥 Exploit | Codefuture CF Image Hosting Script | 11/29/2011 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this was originally reported as a file disclosure vulnerability, but this is… | |
| Modified | Medium (5) | 1.2% | — | Thehostingtool | 9/24/2011 | 6/16/2026 | TheHostingTool (THT) 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/pear/Mail/smtp.php and certain other files. | |
| Modified | High (7.5) | 6.4% | 💥 Exploit | Scripteen Free Image Hosting Script | 8/25/2010 | 6/16/2026 | admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting the cookgid cookie value to 1, a different vector than CVE-2008-3211. | |
| Modified | Medium (6.8) | 0.94% | 💥 Exploit | Scriptsez Mini Hosting Panel | 4/27/2010 | 6/16/2026 | Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for requests that alter administrative settings via a cp action. | |
| Modified | Medium (4.3) | 1.4% | 💥 Exploit | Yabsoft Advanced Image Hosting Script | 12/10/2009 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote attackers to inject arbitrary web script or HTML via the text parameter. | |
| Modified | Medium (4.3) | 1.1% | — | Clixint Image Hosting Script DPI | 12/10/2009 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in images.php in Image Hosting Script DPI 1.1 Final (1.1F) allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: some of these details are obtained from third party information. | |
| Modified | Medium (4.3) | 1.2% | 💥 Exploit | Yabsoft Mega File Hosting Script | 10/9/2009 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the moudi parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modified | High (7.5) | 1.1% | 💥 Exploit | Scripteen Free Image Hosting Script | 8/20/2009 | 6/16/2026 | Multiple SQL injection vulnerabilities in header.php in Scripteen Free Image Hosting Script 2.3 allow remote attackers to execute arbitrary SQL commands via a (1) cookid or (2) cookgid cookie. | |
| Modified | High (7.5) | 0.97% | 💥 Exploit | Webhost-panel Bankoi Webhosting Control Panel | 8/12/2009 | 6/16/2026 | Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. |