Vulnerabilities
Summary — last 7 days
New vulnerabilities2,766▲ 12 vs. last week
Critical / high1,276▼ 252 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)245▲ 227 vs. last week
127 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.5) | 1.00% | 💥 Exploit | Ebayclonescript Ebay Clone | 10/16/2009 | 6/16/2026 | Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view_full_size.php, (3) classifide_ad.php, and (4) crosspromoteitems.php. | |
| Modified | High (7.5) | 2.1% | — | Ezonescripts Dating Website Script | 8/19/2009 | 6/16/2026 | Unrestricted file upload vulnerability in eZoneScripts Dating Website script allows remote attackers to execute arbitrary code via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modified | High (7.5) | 0.91% | 💥 Exploit | Phparcadescript | 8/14/2009 | 6/16/2026 | SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modified | Medium (4.3) | 1.1% | — | Freearcadescript Free Arcade Script | 8/14/2009 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to the default URI under search/. | |
| Modified | High (7.5) | 1.1% | 💥 Exploit | Ebayclonescript Ebay Clone | 7/10/2009 | 6/16/2026 | SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action. | |
| Modified | Medium (4.3) | 1.4% | 💥 Exploit | Arcadetradescript Arcade Trade Script | 7/1/2009 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade Script 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the q parameter in a gamelist action. | |
| Modified | High (7.5) | 1.0% | 💥 Exploit | Mygamescript MY Game Script | 5/29/2009 | 6/16/2026 | SQL injection vulnerability in admin.php in My Game Script 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the username field). NOTE: some of these details are obtained from third party information. | |
| Modified | High (7.5) | 0.99% | 💥 Exploit | Recipescript Recipe Script | 5/18/2009 | 6/16/2026 | Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) Password fields, as reachable from admin/index.php. | |
| Modified | Medium (6.5) | 2.1% | 💥 Exploit | Ezonescripts Living Local | 3/26/2009 | 6/16/2026 | Unrestricted file upload vulnerability in editimage.php in eZoneScripts Living Local 1.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the uploaded file. | |
| Modified | Medium (4.3) | 1.6% | 💥 Exploit | Ezonescripts Living Local | 3/26/2009 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inject arbitrary web script or HTML via the r parameter. | |
| Modified | High (9.3) | 5.6% | 💥 Exploit | Freearcadescript Free Arcade Script | 2/24/2009 | 6/16/2026 | Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter. | |
| Modified | High (7.5) | 1.1% | 💥 Exploit | Ezonescripts Link Trader Script | 2/10/2009 | 6/16/2026 | SQL injection vulnerability in ratelink.php in Link Trader Script allows remote attackers to execute arbitrary SQL commands via the lnkid parameter. | |
| Modified | High (7.5) | 1.2% | 💥 Exploit | Ezonescripts Adult Banner Exchange Website | 2/10/2009 | 6/16/2026 | SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter. | |
| Modified | Medium (6.8) | 3.1% | — | GNU Escript | 12/19/2008 | 6/16/2026 | Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and possibly earlier, might allow remote attackers to execute arbitrary code via an epsf escape sequence with a long filename. | |
| Modified | High (10) | 3.5% | 💥 Exploit | Agaresmedia Themesitescript | 11/13/2008 | 6/16/2026 | PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter. | |
| Modified | High (7.5) | 1.2% | 💥 Exploit | Zeescripts Zeeproperty | 10/21/2008 | 6/16/2026 | SQL injection vulnerability in bannerclick.php in ZeeScripts Zeeproperty allows remote attackers to execute arbitrary SQL commands via the adid parameter. | |
| Modified | High (7.5) | 1.00% | 💥 Exploit | Proarcadescript | 9/22/2008 | 6/16/2026 | SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the random parameter to the default URI. | |
| Modified | High (7.5) | 1.0% | 💥 Exploit | Ezonescripts Living Local | 9/5/2008 | 6/16/2026 | SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter. | |
| Modified | High (7.5) | 1.0% | 💥 Exploit | Phparcadescript | 8/19/2008 | 6/16/2026 | SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse action. | |
| Modified | High (7.5) | 1.2% | 💥 Exploit | Zeescripts Zeereviews | 8/13/2008 | 6/16/2026 | SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (aka ZeeReviews) allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | |
| Modified | Critical (9.8) | 3.5% | 💥 Exploit | Zeescripts Zeebuddy | 8/12/2008 | 6/16/2026 | SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | |
| Modified | High (7.5) | 1.0% | 💥 Exploit | Therealestatescript THE Real Estate Script | 5/27/2008 | 6/16/2026 | SQL injection vulnerability in dpage.php in The Real Estate Script allows remote attackers to execute arbitrary SQL commands via the docID parameter. | |
| Modified | High (7.5) | 0.93% | 💥 Exploit | Phparcadescript | 3/5/2008 | 6/16/2026 | SQL injection vulnerability in index.php in phpArcadeScript 1.0 through 3.0 RC2 allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action. | |
| Modified | High (7.5) | 1.1% | — | Nukescripts Nukesentinel | 10/1/2007 | 6/16/2026 | SQL injection vulnerability in the is_god function in includes/nukesentinel.php in NukeSentinel 2.5.11 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie, a different vector than CVE-2007-5125. | |
| Modified | High (7.5) | 1.1% | — | Nukescripts Nukesentinel | 10/1/2007 | 6/16/2026 | SQL injection vulnerability in the abget_admin function in includes/nukesentinel.php in NukeSentinel 2.5.12 allows remote attackers to execute arbitrary SQL commands via base64-encoded data in an admin cookie. |