Vulnerabilities
Summary — last 7 days
New vulnerabilities2,699▼ 343 vs. last week
Critical / high1,270▼ 197 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)208▼ 123 vs. last week
56 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.1) | 0.40% | — | Nextscripts Social Networks Auto Poster | 12/15/2023 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts: Social Networks Auto-Poster allows Reflected XSS.This issue affects NextScripts: Social Networks Auto-Poster: from n/a through 4.4.2. | |
| Modified | High (7.5) | 1.4% | — | Openteknik Open Source Social Network | 7/25/2022 | 6/17/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home. | |
| Modified | Medium (5.4) | 1.1% | 💥 PoC | Openteknik Open Source Social Network | 7/25/2022 | 6/17/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module. | |
| Modified | High (7.2) | 2.1% | — | Openteknik Open Source Social Network | 7/25/2022 | 6/17/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior… | |
| Modified | Medium (4.8) | 0.89% | — | Openteknik Open Source Social Network | 7/25/2022 | 6/17/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the SitePages module. | |
| Modified | Medium (5.4) | 1.1% | 💥 PoC | Openteknik Open Source Social Network | 7/25/2022 | 6/17/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module. | |
| Modified | Medium (5.4) | 1.1% | 💥 PoC | Openteknik Open Source Social Network | 7/25/2022 | 6/17/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module. | |
| Modified | Medium (5.4) | 0.50% | — | Simple Social Networking Site Project Simple Social Networking Site | 5/24/2022 | 6/17/2026 | Simple Social Networking Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /sns/classes/Users.php?f=save, firstname. | |
| Modified | High (7.2) | 0.97% | — | Simple Social Networking Site Project Simple Social Networking Site | 5/13/2022 | 6/17/2026 | Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=. | |
| Modified | High (7.2) | 0.97% | — | Simple Social Networking Site Project Simple Social Networking Site | 5/13/2022 | 6/17/2026 | Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=posts/view_post&id=. | |
| Modified | High (7.2) | 0.97% | — | Simple Social Networking Site Project Simple Social Networking Site | 5/13/2022 | 6/17/2026 | Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/members/view_member.php?id=. | |
| Modified | Medium (6.5) | 0.87% | — | Simple Social Networking Site Project Simple Social Networking Site | 5/13/2022 | 6/17/2026 | Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img. | |
| Modified | Medium (6.5) | 0.53% | — | Nextscripts Social Networks Auto Poster | 2/1/2022 | 6/17/2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack | |
| Modified | Medium (6.1) | 1.3% | — | Nextscripts Social Networks Auto Poster | 2/1/2022 | 6/17/2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue | |
| Modified | Medium (6.1) | 0.87% | — | Nextscripts Social Networks Auto Poster | 11/1/2021 | 6/17/2026 | The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to load the page in $_GET['page'] along with malicious JavaScript… | |
| Modified | Medium (5.9) | 3.8% | 💥 PoC | Opensource-socialnetwork Open Source Social Network | 3/30/2020 | 6/17/2026 | An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert… | |
| Modified | Critical (9.8) | 1.4% | — | Social Network Project Social Network | 8/26/2019 | 6/17/2026 | Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php. | |
| Modified | Medium (5.3) | 1.5% | — | Humhub Social Network KIT | 7/29/2019 | 6/17/2026 | HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy Information Exposure. | |
| Modified | Critical (9.8) | 3.6% | — | Ambittechnologies Itech B2B ScriptAmbittechnologies Itech Business Networking ScriptAmbittechnologies Itech Caregiver ScriptAmbittechnologies Itech Classifieds Script+8 | 5/9/2019 | 6/17/2026 | Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i… | |
| Modified | Medium (6.1) | 1.3% | — | Nextscripts Social Networks Auto Poster | 3/22/2019 | 6/17/2026 | The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS. | |
| Modified | Critical (9.8) | 10% | 💥 PoC | Designchemical Social Network Tabs | 3/21/2019 | 6/17/2026 | The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover. | |
| Modified | High (7.5) | 2.5% | — | Oracle Social Network | 4/24/2017 | 6/17/2026 | Vulnerability in the Oracle Social Network component of Oracle Fusion Middleware (subcomponent: Android Client). The supported version that is affected is prior to 11.1.12.0.0 (17019101). Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Social… | |
| Modified | Medium (5.4) | 0.27% | — | Freediyhomeimprovement Social Networking | 9/18/2014 | 6/17/2026 | The Social Networking (aka com.wSocialNetworkingSites) application 0.33.13320.99980 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modified | High (7.5) | 1.9% | — | Scripte24shop Social Network Community | 10/25/2012 | 6/16/2026 | SQL injection vulnerability in user.php in Social Network Community 2 allows remote attackers to execute arbitrary SQL commands via the userId parameter. | |
| Modified | High (7.5) | 7.1% | 💥 Exploit | Pangramsoft Pointter PHP Micro-blogging Social Network | 12/22/2010 | 6/16/2026 | Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies. |