Vulnerabilities
Summary — last 7 days
New vulnerabilities2,771▲ 6 vs. last week
Critical / high1,285▼ 246 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)242▲ 224 vs. last week
127 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (10) | 4.2% | 💥 Exploit | Rcms PRO Rgamescript PRO | 7/25/2007 | 6/16/2026 | PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbitrary PHP code via a URL in the id parameter. | |
| Modified | High (7.5) | 1.2% | 💥 Exploit | Flashgamescript | 7/10/2007 | 6/16/2026 | SQL injection vulnerability in index.php in FlashGameScript 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a member action. | |
| Modified | High (7.5) | 1.2% | 💥 Exploit | Gamesitescript | 7/10/2007 | 6/16/2026 | SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field. | |
| Modified | High (7.5) | 3.2% | 💥 Exploit | Nukescripts Nukesentinel | 3/16/2007 | 6/16/2026 | nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for CVE-2007-1172. | |
| Modified | Medium (6.8) | 1.0% | — | Nukescripts Nukesentinel | 3/16/2007 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in NukeSentinel before 2.5.06 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "filters for https:// and http://". | |
| Modified | Medium (6.4) | 1.1% | 💥 Exploit | Nukescripts Nukesentinel | 3/2/2007 | 6/16/2026 | SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, aka the "File Disclosure Exploit." | |
| Modified | High (7.5) | 2.1% | 💥 Exploit | Nukescripts Nukesentinel | 3/2/2007 | 6/16/2026 | SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie. | |
| Modified | High (7.5) | 3.3% | 💥 Exploit | Flashgamescript | 2/22/2007 | 6/16/2026 | PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the func parameter. | |
| Modified | High (7.5) | 1.1% | 💥 Exploit | Scriptphp Messageriescripthp | 12/14/2006 | 6/16/2026 | SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa parameter. | |
| Modified | Medium (6.8) | 2.1% | 💥 Exploit | Scriptphp Messageriescripthp | 12/14/2006 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo parameter to (a) existepseudo.php, the (2) email parameter to (b) existeemail.php, or the (3) pageName or (4) cssform parameter to (c) Contact/contact.php. | |
| Modified | High (7.5) | 11% | 💥 Exploit | Scriptphp Annoncescripthp | 12/12/2006 | 6/16/2026 | Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) email.php, the (2) no parameter in (b) voirannonce.php, the (3) idmembre parameter in (c) admin/admin_membre/fiche_membre.php, and the (4) idannonce parameter in (d)… | |
| Modified | Medium (5) | 1.3% | — | Scriptphp Annoncescripthp | 12/12/2006 | 6/16/2026 | admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre parameter, which discloses the passwords for arbitrary users. | |
| Modified | Medium (6.8) | 2.1% | 💥 Exploit | Scriptphp Annoncescripthp | 12/12/2006 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email parameter in (1) erreurinscription.php, (2) Templates/admin.dwt.php, (3) Templates/commun.dwt.php, (4) membre.dwt.php, and (5) admin/admin_config/Aide.php. | |
| Modified | High (7.5) | 2.4% | 💥 Exploit | Chris MAC Gimescripts Shopping Catalog | 11/15/2006 | 6/16/2026 | PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter. | |
| Modified | High (7.5) | 1.3% | — | Mobescripts Mobile Space Community | 6/23/2006 | 6/16/2026 | SQL injection vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to execute arbitrary SQL commands via the browse parameter. | |
| Modified | Medium (6.8) | 1.4% | — | Mobescripts Mobile Space Community | 6/23/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in index.php in MobeScripts Mobile Space Community 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved… | |
| Modified | High (7.5) | 1.8% | — | Mobescripts Mobile Space Community | 6/23/2006 | 6/16/2026 | Directory traversal vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the uid parameter in the rss page. | |
| Modified | Medium (4.3) | 1.2% | — | Cescripts CAR Classifieds | 6/19/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in index.php in Car Classifieds allows remote attackers to inject arbitrary web script or HTML via the make_id parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modified | Medium (6.8) | 1.8% | 💥 Exploit | Cescripts Event Registration 2checkoutCescripts Event Registration CorporateCescripts Event Registration PaypalCescripts Event Registration Rsvp | 6/16/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id parameter to view-event-details.php or (2) select_events parameter to event-registration.php. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modified | Low (2.6) | 1.2% | — | Cescripts Realty Room Rent | 6/15/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Room Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this script and others at cescripts.com have been addressed and fixed." | |
| Modified | Low (2.6) | 1.2% | — | Cescripts Realty Home Rent | 6/15/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Home Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this script and others at cescripts.com have been addressed and fixed." | |
| Modified | Medium (4.3) | 1.9% | — | Phparcadescript | 3/9/2006 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter in tellafriend.php, (2) the login_status parameter in loginbox.php, (3) the submissionstatus parameter in index.php, the (4)… | |
| Modified | High (7.5) | 2.0% | — | Globalnotescript | 7/6/2005 | 6/16/2026 | read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters. | |
| Modified | Medium (5.1) | 2.3% | — | ApplescriptApple MAC OS XApple MAC OS X Server | 5/4/2005 | 6/16/2026 | The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control… | |
| Modified | Medium (5) | 1.0% | — | Freescripts Visitorbook | 1/5/2004 | 6/16/2026 | FreeScripts VisitorBook LE (visitorbook.pl) does not properly escape line breaks in input, which allows remote attackers to (1) use VisitorBook as an open mail relay, when $mailuser is 1, via extra headers in the email field, or (2) cause the guestbook database to be deleted via a large number of line breaks that… |