Vulnerabilities
Summary — last 7 days
New vulnerabilities2,761▲ 5 vs. last week
Critical / high1,274▼ 254 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)245▲ 227 vs. last week
35 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (5.4) | 0.50% | — | Easy Address Book WEB Server Project Easy Address Book WEB Server | 10/4/2023 | 6/17/2026 | Stored Cross-Site Scripting in Easy Address Book Web Server 1.6 version, through the users_admin.ghp file that affects multiple parameters such as (firstname, homephone, lastname, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate, workzip). This vulnerability allows a remote attacker to… | |
| Modified | Medium (6.1) | 0.42% | — | Easy Address Book WEB Server Project Easy Address Book WEB Server | 10/4/2023 | 6/17/2026 | Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) of the /addrbook.ghp file, allowing an attacker to inject a JavaScript payload specially designed to run when the… | |
| Modified | Critical (9.8) | 0.98% | — | Easy Address Book WEB Server Project Easy Address Book WEB Server | 10/4/2023 | 6/17/2026 | Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an attacker to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the remote machine. | |
| Modified | Critical (9.8) | 0.71% | — | Address Book Project Address Book | 1/7/2023 | 6/17/2026 | A vulnerability was found in LearnMeSomeCodes project3 and classified as critical. This issue affects the function search_first_name of the file search.rb. The manipulation leads to sql injection. The patch is named d3efa17ae9f6b2fc25a6bbcf165cefed17c7035e. It is recommended to apply a patch to fix this issue. The… | |
| Modified | Critical (9.8) | 4.2% | — | Egavilanmedia EGM Address Book | 12/24/2020 | 6/17/2026 | EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution. | |
| Modified | Critical (9.8) | 1.6% | — | Egavilanmedia ECM Address Book | 12/21/2020 | 7/9/2026 | EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user. | |
| Modified | High (8.8) | 0.69% | — | Hallme Woocommerce Address Book | 8/29/2019 | 6/17/2026 | The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks. | |
| Modified | Medium (4.3) | 0.97% | — | Chatelao PHP Address Book | 4/18/2013 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in edit.php in PHP Address Book 8.2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via the Address field. | |
| Modified | High (7.5) | 1.0% | 💥 Exploit | Chatelao PHP Address Book | 4/18/2013 | 6/16/2026 | Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) edit.php or (2) import.php. NOTE: the view.php id vector is already covered by CVE-2008-2565.1 and the edit.php id vector is already covered by CVE-2008-2565.2. | |
| Modified | High (7.5) | 0.63% | — | Chatelao PHP Address Book | 4/9/2013 | 6/16/2026 | Cross-site request forgery (CSRF) vulnerability in addressbook/register/delete_user.php in PHP Address Book 8.2.5 allows remote attackers to hijack the authentication of administrators for requests that delete accounts, a different vulnerability than CVE-2013-0135.1. | |
| Modified | High (7.5) | 3.0% | 💥 Exploit | Chatelao PHP Address Book | 4/9/2013 | 6/16/2026 | Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) addressbook/register/edit_user_save.php; the email parameter to (4)… | |
| Modified | Medium (4.3) | 2.4% | 💥 Exploit | Chatelao PHP Address Book | 9/9/2012 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. NOTE: the index.php vector is already covered by CVE-2008-2566. | |
| Modified | High (7.5) | 1.2% | 💥 Exploit | Chatelao PHP Address Book | 9/9/2012 | 6/16/2026 | Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. NOTE: the edit.php vector is already covered by CVE-2008-2565. | |
| Modified | Medium (4.3) | 1.8% | 💥 Exploit | Chatelao PHP Address Book | 5/21/2012 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to group.php, or the (2) target_language or (3) target_flag parameter to translate.php. | |
| Modified | Medium (6.8) | 1.3% | — | Phpkobo Address Book Script | 3/23/2010 | 6/16/2026 | Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter. NOTE: the provenance of this information is unknown;… | |
| Modified | Medium (6.8) | 2.3% | 💥 Exploit | Phpkobo Address Book Script | 3/23/2010 | 6/16/2026 | Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter. | |
| Modified | Medium (6.8) | 0.91% | 💥 Exploit | Chatelao PHP Address Book | 7/27/2009 | 6/16/2026 | Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565. | |
| Modified | Medium (6.8) | 4.1% | 💥 Exploit | Studiolounge Address Book | 4/29/2009 | 6/16/2026 | Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in profiles/. | |
| Modified | High (7.5) | 1.9% | 💥 Exploit | Php-address Book | 6/6/2008 | 6/16/2026 | Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) edit.php. NOTE: it was later reported that 4.0.x is also affected. | |
| Modified | Medium (4.3) | 1.5% | 💥 Exploit | Php-address Book | 6/6/2008 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI. | |
| Modified | High (9.3) | 7.8% | 💥 Exploit | Joomla NFN Address BookMambo NFN Address Book | 3/22/2007 | 6/16/2026 | Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2)… | |
| Modified | Medium (6.4) | 15% | — | Zephyrsoft Toolbox Address Book Continued | 2/27/2007 | 6/16/2026 | Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php, a variant of a SQL injection issue that was… | |
| Modified | Medium (6.4) | 1.1% | — | Zephyrsoft Toolbox Address Book Continued | 2/27/2007 | 6/16/2026 | Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php. NOTE: some of these details are obtained from third… | |
| Modified | Medium (5) | 1.8% | — | THE Address Book | 12/31/2006 | 6/16/2026 | Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote attackers to include arbitrary files via a .. (dot dot) in the language parameter. | |
| Modified | Medium (5) | 1.3% | — | THE Address Book | 12/31/2006 | 6/16/2026 | Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demonstrated by deleting arbitrary users via the id parameter in a deleteuser action in users.php. |