Vulnerabilities

Summary — last 7 days

New vulnerabilities2,771▲ 6 vs. last week
Critical / high1,285▼ 246 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)242▲ 224 vs. last week
–

127 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (10)4.2%💥 ExploitRcms PRO Rgamescript PRO7/25/20076/16/2026
PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
ModifiedHigh (7.5)1.2%💥 ExploitFlashgamescript7/10/20076/16/2026
SQL injection vulnerability in index.php in FlashGameScript 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a member action.
ModifiedHigh (7.5)1.2%💥 ExploitGamesitescript7/10/20076/16/2026
SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.
ModifiedHigh (7.5)3.2%💥 ExploitNukescripts Nukesentinel3/16/20076/16/2026
nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for CVE-2007-1172.
ModifiedMedium (6.8)1.0%—Nukescripts Nukesentinel3/16/20076/16/2026
Cross-site scripting (XSS) vulnerability in NukeSentinel before 2.5.06 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "filters for https:// and http://".
ModifiedMedium (6.4)1.1%💥 ExploitNukescripts Nukesentinel3/2/20076/16/2026
SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, aka the "File Disclosure Exploit."
ModifiedHigh (7.5)2.1%💥 ExploitNukescripts Nukesentinel3/2/20076/16/2026
SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie.
ModifiedHigh (7.5)3.3%💥 ExploitFlashgamescript2/22/20076/16/2026
PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the func parameter.
ModifiedHigh (7.5)1.1%💥 ExploitScriptphp Messageriescripthp12/14/20066/16/2026
SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa parameter.
ModifiedMedium (6.8)2.1%💥 ExploitScriptphp Messageriescripthp12/14/20066/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo parameter to (a) existepseudo.php, the (2) email parameter to (b) existeemail.php, or the (3) pageName or (4) cssform parameter to (c) Contact/contact.php.
ModifiedHigh (7.5)11%💥 ExploitScriptphp Annoncescripthp12/12/20066/16/2026
Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) email.php, the (2) no parameter in (b) voirannonce.php, the (3) idmembre parameter in (c) admin/admin_membre/fiche_membre.php, and the (4) idannonce parameter in (d)…
ModifiedMedium (5)1.3%—Scriptphp Annoncescripthp12/12/20066/16/2026
admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre parameter, which discloses the passwords for arbitrary users.
ModifiedMedium (6.8)2.1%💥 ExploitScriptphp Annoncescripthp12/12/20066/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email parameter in (1) erreurinscription.php, (2) Templates/admin.dwt.php, (3) Templates/commun.dwt.php, (4) membre.dwt.php, and (5) admin/admin_config/Aide.php.
ModifiedHigh (7.5)2.4%💥 ExploitChris MAC Gimescripts Shopping Catalog11/15/20066/16/2026
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter.
ModifiedHigh (7.5)1.3%—Mobescripts Mobile Space Community6/23/20066/16/2026
SQL injection vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to execute arbitrary SQL commands via the browse parameter.
ModifiedMedium (6.8)1.4%—Mobescripts Mobile Space Community6/23/20066/16/2026
Cross-site scripting (XSS) vulnerability in index.php in MobeScripts Mobile Space Community 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved…
ModifiedHigh (7.5)1.8%—Mobescripts Mobile Space Community6/23/20066/16/2026
Directory traversal vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the uid parameter in the rss page.
ModifiedMedium (4.3)1.2%—Cescripts CAR Classifieds6/19/20066/16/2026
Cross-site scripting (XSS) vulnerability in index.php in Car Classifieds allows remote attackers to inject arbitrary web script or HTML via the make_id parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModifiedMedium (6.8)1.8%💥 ExploitCescripts Event Registration 2checkoutCescripts Event Registration CorporateCescripts Event Registration PaypalCescripts Event Registration Rsvp6/16/20066/16/2026
Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id parameter to view-event-details.php or (2) select_events parameter to event-registration.php. NOTE: the provenance of this information is unknown; the details are obtained…
ModifiedLow (2.6)1.2%—Cescripts Realty Room Rent6/15/20066/16/2026
Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Room Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this script and others at cescripts.com have been addressed and fixed."
ModifiedLow (2.6)1.2%—Cescripts Realty Home Rent6/15/20066/16/2026
Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Home Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this script and others at cescripts.com have been addressed and fixed."
ModifiedMedium (4.3)1.9%—Phparcadescript3/9/20066/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter in tellafriend.php, (2) the login_status parameter in loginbox.php, (3) the submissionstatus parameter in index.php, the (4)…
ModifiedHigh (7.5)2.0%—Globalnotescript7/6/20056/16/2026
read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.
ModifiedMedium (5.1)2.3%—ApplescriptApple MAC OS XApple MAC OS X Server5/4/20056/16/2026
The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control…
ModifiedMedium (5)1.0%—Freescripts Visitorbook1/5/20046/16/2026
FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that…