Vulnerabilities
Summary — last 7 days
New vulnerabilities2,847▼ 221 vs. last week
Critical / high1,330▼ 168 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)222▼ 99 vs. last week
143 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.5) | 1.1% | 💥 Exploit | Turnkeyforms WEB Hosting Directory | 8/12/2009 | 6/16/2026 | SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQL commands via the password field. | |
| Modified | High (7.5) | 2.8% | 💥 Exploit | Turnkeyforms WEB Hosting Directory | 8/12/2009 | 6/16/2026 | TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain a database backup via a direct request to admin/backup/db. | |
| Modified | High (7.5) | 3.1% | 💥 Exploit | Turnkeyforms WEB Hosting Directory | 8/12/2009 | 6/16/2026 | TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cookie to the target username. | |
| Modified | High (7.5) | 1.0% | 💥 Exploit | Scripts-for-sites EZ Hosting Directory | 5/1/2009 | 6/16/2026 | SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Hosting Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. | |
| Modified | High (7.5) | 2.0% | 💥 Exploit | Wh-com COM Webhosting | 4/7/2009 | 6/16/2026 | SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | |
| Modified | High (7.5) | 1.0% | 💥 Exploit | Yabsoft Advanced Image Hosting Script | 3/20/2009 | 6/16/2026 | SQL injection vulnerability in gallery_list.php in YABSoft Advanced Image Hosting (AIH) Script 2.3 allows remote attackers to execute arbitrary SQL commands via the gal parameter. | |
| Modified | High (7.5) | 2.5% | 💥 Exploit | Yabsoft Mega File Hosting Script | 3/19/2009 | 6/16/2026 | PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences. | |
| Modified | High (7.5) | 1.1% | 💥 Exploit | Prozilla Hosting Index | 2/11/2009 | 6/16/2026 | SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action, a different vector than CVE-2008-2083. | |
| Modified | Medium (4.3) | 2.3% | 💥 Exploit | Scriptsez Mini Hosting Panel | 2/6/2009 | 6/16/2026 | Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action. | |
| Modified | High (7.5) | 0.97% | 💥 Exploit | Yourfreeworld Classifieds Hosting Script | 11/4/2008 | 6/16/2026 | SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modified | High (7.5) | 1.0% | 💥 Exploit | Yourfreeworld Autoresponder Hosting Script | 11/4/2008 | 6/16/2026 | SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modified | High (7.5) | 2.5% | 💥 Exploit | Fhm-script Free Hosting Manager | 8/8/2008 | 6/16/2026 | Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by setting both the adminuser and loggedin cookies. | |
| Modified | High (10) | 3.5% | 💥 Exploit | Jnshosts PHP Hosting Directory | 8/4/2008 | 6/16/2026 | PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the rd parameter. | |
| Modified | High (7.5) | 2.5% | 💥 Exploit | Jnshosts PHP Hosting Directory | 8/4/2008 | 6/16/2026 | JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the "adm" cookie value to 1. | |
| Modified | High (7.5) | 0.95% | 💥 Exploit | Scripteen Free Image Hosting Script | 7/18/2008 | 6/16/2026 | Multiple SQL injection vulnerabilities in Scripteen Free Image Hosting Script 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/login.php, or the (3) uname or (4) pass parameter to login.php. NOTE: the provenance of this information is unknown; the… | |
| Modified | High (7.5) | 3.3% | 💥 Exploit | Scripteen Free Image Hosting Script | 7/18/2008 | 6/16/2026 | Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1. | |
| Modified | Medium (6.5) | 0.90% | 💥 Exploit | Yabsoft Mega File Hosting Script | 6/3/2008 | 6/16/2026 | SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter. | |
| Modified | High (7.5) | 0.97% | 💥 Exploit | Yabsoft Advanced Image Hosting Script | 6/3/2008 | 6/16/2026 | SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t parameter. | |
| Analyzed | Medium (6.8) | 1.4% | 💥 Exploit | Softbizscripts WEB Hosting Directory Script | 5/6/2008 | 6/16/2026 | SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817. | |
| Modified | Medium (6.8) | 1.1% | 💥 Exploit | Prozilla Hosting Index | 5/5/2008 | 6/16/2026 | SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. | |
| Modified | Medium (4.9) | 4.5% | 💥 Exploit | Hosting Controller | 12/20/2007 | 6/16/2026 | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete "gateway information" via a request to OpenApi/GatewayVariables.asp. | |
| Modified | Medium (5.5) | 2.8% | 💥 Exploit | Hosting Controller | 12/20/2007 | 6/16/2026 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames; and (2) certain XML HTTP requests to hosting/css.asp using Microsoft.XMLHTTP or MSXML2.XMLHTTP objects,… | |
| Modified | High (10) | 12% | 💥 Exploit | Hosting Controller | 12/20/2007 | 6/16/2026 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/displays.asp with the DecideAction and ChangeSkin parameters. | |
| Modified | High (7.5) | 1.2% | 💥 Exploit | Hosting Controller | 12/20/2007 | 6/16/2026 | Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2) loginname parameters to Hosting/Addreseller.asp, (3) the sortfield parameter to accounts/accountmanager.asp, (4) the GateWayID parameter… | |
| Modified | Medium (6.8) | 2.7% | 💥 Exploit | Hosting Controller | 12/20/2007 | 6/16/2026 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the loginname and password parameters set, when preceded by certain requests to hosting/default.asp and hosting/selectdomain.asp, a related issue to CVE-2005-1654. |