Vulnerabilities

Summary — last 7 days

New vulnerabilities2,847▼ 221 vs. last week
Critical / high1,330▼ 168 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)222▼ 99 vs. last week
–

143 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.5)1.1%💥 ExploitTurnkeyforms WEB Hosting Directory8/12/20096/16/2026
SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQL commands via the password field.
ModifiedHigh (7.5)2.8%💥 ExploitTurnkeyforms WEB Hosting Directory8/12/20096/16/2026
TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain a database backup via a direct request to admin/backup/db.
ModifiedHigh (7.5)3.1%💥 ExploitTurnkeyforms WEB Hosting Directory8/12/20096/16/2026
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cookie to the target username.
ModifiedHigh (7.5)1.0%💥 ExploitScripts-for-sites EZ Hosting Directory5/1/20096/16/2026
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Hosting Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
ModifiedHigh (7.5)2.0%💥 ExploitWh-com COM Webhosting4/7/20096/16/2026
SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.
ModifiedHigh (7.5)1.0%💥 ExploitYabsoft Advanced Image Hosting Script3/20/20096/16/2026
SQL injection vulnerability in gallery_list.php in YABSoft Advanced Image Hosting (AIH) Script 2.3 allows remote attackers to execute arbitrary SQL commands via the gal parameter.
ModifiedHigh (7.5)2.5%💥 ExploitYabsoft Mega File Hosting Script3/19/20096/16/2026
PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
ModifiedHigh (7.5)1.1%💥 ExploitProzilla Hosting Index2/11/20096/16/2026
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action, a different vector than CVE-2008-2083.
ModifiedMedium (4.3)2.3%💥 ExploitScriptsez Mini Hosting Panel2/6/20096/16/2026
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action.
ModifiedHigh (7.5)0.97%💥 ExploitYourfreeworld Classifieds Hosting Script11/4/20086/16/2026
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModifiedHigh (7.5)1.0%💥 ExploitYourfreeworld Autoresponder Hosting Script11/4/20086/16/2026
SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModifiedHigh (7.5)2.5%💥 ExploitFhm-script Free Hosting Manager8/8/20086/16/2026
Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by setting both the adminuser and loggedin cookies.
ModifiedHigh (10)3.5%💥 ExploitJnshosts PHP Hosting Directory8/4/20086/16/2026
PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the rd parameter.
ModifiedHigh (7.5)2.5%💥 ExploitJnshosts PHP Hosting Directory8/4/20086/16/2026
JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the "adm" cookie value to 1.
ModifiedHigh (7.5)0.95%💥 ExploitScripteen Free Image Hosting Script7/18/20086/16/2026
Multiple SQL injection vulnerabilities in Scripteen Free Image Hosting Script 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/login.php, or the (3) uname or (4) pass parameter to login.php. NOTE: the provenance of this information is unknown; the…
ModifiedHigh (7.5)3.3%💥 ExploitScripteen Free Image Hosting Script7/18/20086/16/2026
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1.
ModifiedMedium (6.5)0.90%💥 ExploitYabsoft Mega File Hosting Script6/3/20086/16/2026
SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter.
ModifiedHigh (7.5)0.97%💥 ExploitYabsoft Advanced Image Hosting Script6/3/20086/16/2026
SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t parameter.
AnalyzedMedium (6.8)1.4%💥 ExploitSoftbizscripts WEB Hosting Directory Script5/6/20086/16/2026
SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.
ModifiedMedium (6.8)1.1%💥 ExploitProzilla Hosting Index5/5/20086/16/2026
SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
ModifiedMedium (4.9)4.5%💥 ExploitHosting Controller12/20/20076/16/2026
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete "gateway information" via a request to OpenApi/GatewayVariables.asp.
ModifiedMedium (5.5)2.8%💥 ExploitHosting Controller12/20/20076/16/2026
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames; and (2) certain XML HTTP requests to hosting/css.asp using Microsoft.XMLHTTP or MSXML2.XMLHTTP objects,…
ModifiedHigh (10)12%💥 ExploitHosting Controller12/20/20076/16/2026
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/displays.asp with the DecideAction and ChangeSkin parameters.
ModifiedHigh (7.5)1.2%💥 ExploitHosting Controller12/20/20076/16/2026
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2) loginname parameters to Hosting/Addreseller.asp, (3) the sortfield parameter to accounts/accountmanager.asp, (4) the GateWayID parameter…
ModifiedMedium (6.8)2.7%💥 ExploitHosting Controller12/20/20076/16/2026
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the loginname and password parameters set, when preceded by certain requests to hosting/default.asp and hosting/selectdomain.asp, a related issue to CVE-2005-1654.
Orbitaley — Vulnerabilities