Vulnerabilities

Summary — last 7 days

New vulnerabilities2,766▲ 12 vs. last week
Critical / high1,276▼ 252 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)245▲ 227 vs. last week
–

127 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.5)1.00%💥 ExploitEbayclonescript Ebay Clone10/16/20096/16/2026
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view_full_size.php, (3) classifide_ad.php, and (4) crosspromoteitems.php.
ModifiedHigh (7.5)2.1%—Ezonescripts Dating Website Script8/19/20096/16/2026
Unrestricted file upload vulnerability in eZoneScripts Dating Website script allows remote attackers to execute arbitrary code via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModifiedHigh (7.5)0.91%💥 ExploitPhparcadescript8/14/20096/16/2026
SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModifiedMedium (4.3)1.1%—Freearcadescript Free Arcade Script8/14/20096/16/2026
Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to the default URI under search/.
ModifiedHigh (7.5)1.1%💥 ExploitEbayclonescript Ebay Clone7/10/20096/16/2026
SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action.
ModifiedMedium (4.3)1.4%💥 ExploitArcadetradescript Arcade Trade Script7/1/20096/16/2026
Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade Script 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the q parameter in a gamelist action.
ModifiedHigh (7.5)1.0%💥 ExploitMygamescript MY Game Script5/29/20096/16/2026
SQL injection vulnerability in admin.php in My Game Script 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the username field). NOTE: some of these details are obtained from third party information.
ModifiedHigh (7.5)0.99%💥 ExploitRecipescript Recipe Script5/18/20096/16/2026
Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) Password fields, as reachable from admin/index.php.
ModifiedMedium (6.5)2.1%💥 ExploitEzonescripts Living Local3/26/20096/16/2026
Unrestricted file upload vulnerability in editimage.php in eZoneScripts Living Local 1.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the uploaded file.
ModifiedMedium (4.3)1.6%💥 ExploitEzonescripts Living Local3/26/20096/16/2026
Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inject arbitrary web script or HTML via the r parameter.
ModifiedHigh (9.3)5.6%💥 ExploitFreearcadescript Free Arcade Script2/24/20096/16/2026
Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.
ModifiedHigh (7.5)1.1%💥 ExploitEzonescripts Link Trader Script2/10/20096/16/2026
SQL injection vulnerability in ratelink.php in Link Trader Script allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.
ModifiedHigh (7.5)1.2%💥 ExploitEzonescripts Adult Banner Exchange Website2/10/20096/16/2026
SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter.
ModifiedMedium (6.8)3.1%—GNU Escript12/19/20086/16/2026
Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and possibly earlier, might allow remote attackers to execute arbitrary code via an epsf escape sequence with a long filename.
ModifiedHigh (10)3.5%💥 ExploitAgaresmedia Themesitescript11/13/20086/16/2026
PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter.
ModifiedHigh (7.5)1.2%💥 ExploitZeescripts Zeeproperty10/21/20086/16/2026
SQL injection vulnerability in bannerclick.php in ZeeScripts Zeeproperty allows remote attackers to execute arbitrary SQL commands via the adid parameter.
ModifiedHigh (7.5)1.00%💥 ExploitProarcadescript9/22/20086/16/2026
SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the random parameter to the default URI.
ModifiedHigh (7.5)1.0%💥 ExploitEzonescripts Living Local9/5/20086/16/2026
SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.
ModifiedHigh (7.5)1.0%💥 ExploitPhparcadescript8/19/20086/16/2026
SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse action.
ModifiedHigh (7.5)1.2%💥 ExploitZeescripts Zeereviews8/13/20086/16/2026
SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (aka ZeeReviews) allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
ModifiedCritical (9.8)3.5%💥 ExploitZeescripts Zeebuddy8/12/20086/16/2026
SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter.
ModifiedHigh (7.5)1.0%💥 ExploitTherealestatescript THE Real Estate Script5/27/20086/16/2026
SQL injection vulnerability in dpage.php in The Real Estate Script allows remote attackers to execute arbitrary SQL commands via the docID parameter.
ModifiedHigh (7.5)0.93%💥 ExploitPhparcadescript3/5/20086/16/2026
SQL injection vulnerability in index.php in phpArcadeScript 1.0 through 3.0 RC2 allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action.
ModifiedHigh (7.5)1.1%—Nukescripts Nukesentinel10/1/20076/16/2026
SQL injection vulnerability in the is_god function in includes/nukesentinel.php in NukeSentinel 2.5.11 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie, a different vector than CVE-2007-5125.
ModifiedHigh (7.5)1.1%—Nukescripts Nukesentinel10/1/20076/16/2026
SQL injection vulnerability in the abget_admin function in includes/nukesentinel.php in NukeSentinel 2.5.12 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie.