Vulnerabilities
Summary — last 7 days
New vulnerabilities2,697▼ 350 vs. last week
Critical / high1,260▼ 214 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)210▼ 117 vs. last week
56 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (4.3) | 1.5% | 💥 Exploit | Abk-soft Chameleon Social Networking | 12/1/2010 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in forum_new_topic.php in Chameleon Social Networking allow remote attackers to inject arbitrary web script or HTML via the (1) thread_title and (2) thread_description parameters in a message. | |
| Modified | High (7.5) | 0.97% | 💥 Exploit | Phpscripte24 WEB Social Network Freunde Community | 5/12/2010 | 6/16/2026 | SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action. | |
| Modified | Medium (4.3) | 1.5% | 💥 Exploit | Marcello Brandao Yogurt Social Network Module | 8/13/2008 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt Social Network module 3.2 rc1 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the uid parameter to (1) friends.php, (2) seutubo.php, (3) album.php, (4) scrapbook.php, (5) index.php, or (6) tribes.php; or (7) the description… | |
| Modified | Medium (6.8) | 5.8% | 💥 Exploit | Datecomm Social Networking Script | 11/20/2007 | 6/16/2026 | PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. | |
| Modified | High (7.5) | 1.1% | 💥 Exploit | Datecomm Social Networking Script | 11/15/2007 | 6/16/2026 | SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forums page. | |
| Modified | High (7.5) | 1.3% | — | Psi-labs Social Networking Script Psisns | 9/14/2007 | 6/16/2026 | SQL injection vulnerability in profile/myprofile.php in psi-labs.com social networking script (psisns), probably 1.0, allows remote attackers to execute arbitrary SQL commands via the u parameter. |