Vulnerabilities
Summary — last 7 days
New vulnerabilities2,771▼ 1 vs. last week
Critical / high1,280▼ 248 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 211 vs. last week
127 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (6.1) | 0.45% | — | Bdtask G-prescription Gynaecology & OBS Consultation | 3/8/2024 | 6/17/2026 | A vulnerability, which was classified as problematic, was found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0. Affected is an unknown function of the component OBS Patient/Gynee Prescription. The manipulation of the argument Patient Title/Full Name/Address/Cheif Complain/LMP/Menstrual Edd/OBS… | |
| Analyzed | Medium (6.1) | 0.49% | — | Bdtask G-prescription Gynaecology & OBS Consultation | 3/8/2024 | 6/17/2026 | A vulnerability, which was classified as problematic, has been found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0. This issue affects some unknown processing of the file /Home/Index of the component Prescription Dashboard. The manipulation of the argument Title leads to cross site scripting.… | |
| Modified | High (7.1) | 0.59% | — | Sequelizejs Sequelize-typescript | 11/24/2023 | 6/17/2026 | Prototype Pollution in GitHub repository robinbuschmann/sequelize-typescript prior to 2.1.6. | |
| Modified | Medium (6.1) | 0.38% | — | Simplecoding Terms Descriptions | 8/10/2023 | 6/17/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vladimir Statsenko Terms descriptions plugin <= 3.4.4 versions. | |
| Modified | Critical (9.8) | 1.8% | — | Typescript Deep Merge Project Typescript Deep Merge | 8/9/2022 | 6/17/2026 | The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function. | |
| Modified | Medium (6.1) | 1.0% | — | Mediawiki Shortdescription | 1/24/2022 | 6/17/2026 | ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vulnerability exists in versions prior to 2.3.4. On a wiki that has the ShortDescription enabled, XSS can be triggered on any page or the page with the action=info parameter, which displays the… | |
| Modified | Medium (5.4) | 0.73% | — | Jenkins Description Column | 9/16/2020 | 6/17/2026 | Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | |
| Modified | High (8.8) | 5.9% | — | Microsoft Azure Storage ExplorerMicrosoft TypescriptMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+1 | 7/14/2020 | 6/17/2026 | An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'. | |
| Modified | High (7.5) | 1.2% | — | Coffescript Project Coffescript | 6/7/2018 | 6/17/2026 | The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. | |
| Modified | High (7.5) | 1.1% | — | Coffescript Project Coffescript | 6/7/2018 | 6/17/2026 | The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. | |
| Modified | High (7.5) | 1.1% | — | Coffescript Project Coffescript | 6/7/2018 | 6/17/2026 | The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. | |
| Modified | High (7.5) | 1.2% | — | Cofeescript Project Cofeescript | 6/7/2018 | 6/17/2026 | The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation. | |
| Modified | Medium (5.4) | 0.49% | — | Fortunescripts Lynda Clone | 12/27/2017 | 6/17/2026 | FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile. | |
| Modified | High (8.8) | 0.46% | — | Fortunescripts Lynda Clone | 12/27/2017 | 6/17/2026 | FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel. | |
| Modified | Critical (9.8) | 3.0% | 💥 Exploit | Fortunescripts Ebay Clone | 12/13/2017 | 6/17/2026 | FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter. | |
| Modified | Critical (9.8) | 3.0% | 💥 Exploit | Zeescripts Zeebuddy | 10/29/2017 | 6/17/2026 | ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604. | |
| Modified | High (7.5) | 1.5% | — | Audiosharescript Audioshare | 6/23/2015 | 6/17/2026 | PHP remote file inclusion vulnerability in ajax/myajaxphp.php in AudioShare 2.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the config['basedir'] parameter. | |
| Modified | Medium (4.3) | 1.0% | — | Audiosharescript Audioshare | 6/23/2015 | 6/17/2026 | Cross-site scripting (XSS) vulnerability in forgot.php in AudioShare 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the email parameter. | |
| Modified | High (7.5) | 1.7% | — | Artonx.org Activescriptruby | 4/16/2012 | 6/16/2026 | GRScript18.dll before 1.2.2.0 in ActiveScriptRuby (ASR) before 1.8.7 does not properly restrict interaction with an Internet Explorer ActiveX environment, which allows remote attackers to execute arbitrary Ruby code via a crafted HTML document. | |
| Modified | High (7.5) | 1.2% | 💥 Exploit | Ypninc Jokescript | 11/1/2011 | 6/16/2026 | SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands via the ypncat_id parameter. | |
| Modified | Medium (6.8) | 1.8% | — | Apple MAC OS XApplescriptApple MAC OS X Server | 3/23/2011 | 6/16/2026 | Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (2) display alert command in a dialog in an AppleScript Studio… | |
| Modified | High (7.5) | 0.97% | 💥 Exploit | Gamescript | 4/13/2010 | 6/16/2026 | SQL injection vulnerability in index.php in GameScript (GS) 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action. | |
| Modified | High (7.5) | 0.97% | 💥 Exploit | Proarcadescript | 3/23/2010 | 6/16/2026 | SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modified | High (7.5) | 1.00% | 💥 Exploit | Junglescripts Ajax Short URL Script | 3/18/2010 | 6/16/2026 | SQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modified | High (7.5) | 2.3% | 💥 Exploit | Arcadetradescript Arcade Trade Script | 11/18/2009 | 6/16/2026 | Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true. |