Vulnerabilities

Summary — last 7 days

New vulnerabilities2,771▼ 1 vs. last week
Critical / high1,280▼ 248 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)244▲ 211 vs. last week
–

127 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (6.1)0.45%—Bdtask G-prescription Gynaecology & OBS Consultation3/8/20246/17/2026
A vulnerability, which was classified as problematic, was found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0. Affected is an unknown function of the component OBS Patient/Gynee Prescription. The manipulation of the argument Patient Title/Full Name/Address/Cheif Complain/LMP/Menstrual Edd/OBS…
AnalyzedMedium (6.1)0.49%—Bdtask G-prescription Gynaecology & OBS Consultation3/8/20246/17/2026
A vulnerability, which was classified as problematic, has been found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0. This issue affects some unknown processing of the file /Home/Index of the component Prescription Dashboard. The manipulation of the argument Title leads to cross site scripting.…
ModifiedHigh (7.1)0.59%—Sequelizejs Sequelize-typescript11/24/20236/17/2026
Prototype Pollution in GitHub repository robinbuschmann/sequelize-typescript prior to 2.1.6.
ModifiedMedium (6.1)0.38%—Simplecoding Terms Descriptions8/10/20236/17/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vladimir Statsenko Terms descriptions plugin <= 3.4.4 versions.
ModifiedCritical (9.8)1.8%—Typescript Deep Merge Project Typescript Deep Merge8/9/20226/17/2026
The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.
ModifiedMedium (6.1)1.0%—Mediawiki Shortdescription1/24/20226/17/2026
ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vulnerability exists in versions prior to 2.3.4. On a wiki that has the ShortDescription enabled, XSS can be triggered on any page or the page with the action=info parameter, which displays the…
ModifiedMedium (5.4)0.73%—Jenkins Description Column9/16/20206/17/2026
Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
ModifiedHigh (8.8)5.9%—Microsoft Azure Storage ExplorerMicrosoft TypescriptMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+17/14/20206/17/2026
An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.
ModifiedHigh (7.5)1.2%—Coffescript Project Coffescript6/7/20186/17/2026
The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
ModifiedHigh (7.5)1.1%—Coffescript Project Coffescript6/7/20186/17/2026
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
ModifiedHigh (7.5)1.1%—Coffescript Project Coffescript6/7/20186/17/2026
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
ModifiedHigh (7.5)1.2%—Cofeescript Project Cofeescript6/7/20186/17/2026
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
ModifiedMedium (5.4)0.49%—Fortunescripts Lynda Clone12/27/20176/17/2026
FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile.
ModifiedHigh (8.8)0.46%—Fortunescripts Lynda Clone12/27/20176/17/2026
FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.
ModifiedCritical (9.8)3.0%💥 ExploitFortunescripts Ebay Clone12/13/20176/17/2026
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.
ModifiedCritical (9.8)3.0%💥 ExploitZeescripts Zeebuddy10/29/20176/17/2026
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604.
ModifiedHigh (7.5)1.5%—Audiosharescript Audioshare6/23/20156/17/2026
PHP remote file inclusion vulnerability in ajax/myajaxphp.php in AudioShare 2.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the config['basedir'] parameter.
ModifiedMedium (4.3)1.0%—Audiosharescript Audioshare6/23/20156/17/2026
Cross-site scripting (XSS) vulnerability in forgot.php in AudioShare 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
ModifiedHigh (7.5)1.7%—Artonx.org Activescriptruby4/16/20126/16/2026
GRScript18.dll before 1.2.2.0 in ActiveScriptRuby (ASR) before 1.8.7 does not properly restrict interaction with an Internet Explorer ActiveX environment, which allows remote attackers to execute arbitrary Ruby code via a crafted HTML document.
ModifiedHigh (7.5)1.2%💥 ExploitYpninc Jokescript11/1/20116/16/2026
SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands via the ypncat_id parameter.
ModifiedMedium (6.8)1.8%—Apple MAC OS XApplescriptApple MAC OS X Server3/23/20116/16/2026
Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (2) display alert command in a dialog in an AppleScript Studio…
ModifiedHigh (7.5)0.97%💥 ExploitGamescript4/13/20106/16/2026
SQL injection vulnerability in index.php in GameScript (GS) 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action.
ModifiedHigh (7.5)0.97%💥 ExploitProarcadescript3/23/20106/16/2026
SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModifiedHigh (7.5)1.00%💥 ExploitJunglescripts Ajax Short URL Script3/18/20106/16/2026
SQL injection vulnerability in x/login in JungleScripts Ajax Short Url Script allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModifiedHigh (7.5)2.3%💥 ExploitArcadetradescript Arcade Trade Script11/18/20096/16/2026
Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true.