Vulnerabilities

Summary — last 7 days

New vulnerabilities2,761▲ 5 vs. last week
Critical / high1,274▼ 254 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)245▲ 227 vs. last week
–

35 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (5.4)0.50%—Easy Address Book WEB Server Project Easy Address Book WEB Server10/4/20236/17/2026
Stored Cross-Site Scripting in Easy Address Book Web Server 1.6 version, through the users_admin.ghp file that affects multiple parameters such as (firstname, homephone, lastname, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate, workzip). This vulnerability allows a remote attacker to…
ModifiedMedium (6.1)0.42%—Easy Address Book WEB Server Project Easy Address Book WEB Server10/4/20236/17/2026
Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) of the /addrbook.ghp file, allowing an attacker to inject a JavaScript payload specially designed to run when the…
ModifiedCritical (9.8)0.98%—Easy Address Book WEB Server Project Easy Address Book WEB Server10/4/20236/17/2026
Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an attacker to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the remote machine.
ModifiedCritical (9.8)0.71%—Address Book Project Address Book1/7/20236/17/2026
A vulnerability was found in LearnMeSomeCodes project3 and classified as critical. This issue affects the function search_first_name of the file search.rb. The manipulation leads to sql injection. The patch is named d3efa17ae9f6b2fc25a6bbcf165cefed17c7035e. It is recommended to apply a patch to fix this issue. The…
ModifiedCritical (9.8)4.2%—Egavilanmedia EGM Address Book12/24/20206/17/2026
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
ModifiedCritical (9.8)1.6%—Egavilanmedia ECM Address Book12/21/20207/9/2026
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
ModifiedHigh (8.8)0.69%—Hallme Woocommerce Address Book8/29/20196/17/2026
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
ModifiedMedium (4.3)0.97%—Chatelao PHP Address Book4/18/20136/16/2026
Cross-site scripting (XSS) vulnerability in edit.php in PHP Address Book 8.2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via the Address field.
ModifiedHigh (7.5)1.0%💥 ExploitChatelao PHP Address Book4/18/20136/16/2026
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) edit.php or (2) import.php. NOTE: the view.php id vector is already covered by CVE-2008-2565.1 and the edit.php id vector is already covered by CVE-2008-2565.2.
ModifiedHigh (7.5)0.63%—Chatelao PHP Address Book4/9/20136/16/2026
Cross-site request forgery (CSRF) vulnerability in addressbook/register/delete_user.php in PHP Address Book 8.2.5 allows remote attackers to hijack the authentication of administrators for requests that delete accounts, a different vulnerability than CVE-2013-0135.1.
ModifiedHigh (7.5)3.0%💥 ExploitChatelao PHP Address Book4/9/20136/16/2026
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) addressbook/register/edit_user_save.php; the email parameter to (4)…
ModifiedMedium (4.3)2.4%💥 ExploitChatelao PHP Address Book9/9/20126/16/2026
Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. NOTE: the index.php vector is already covered by CVE-2008-2566.
ModifiedHigh (7.5)1.2%💥 ExploitChatelao PHP Address Book9/9/20126/16/2026
Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id parameter to vcard.php. NOTE: the edit.php vector is already covered by CVE-2008-2565.
ModifiedMedium (4.3)1.8%💥 ExploitChatelao PHP Address Book5/21/20126/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to group.php, or the (2) target_language or (3) target_flag parameter to translate.php.
ModifiedMedium (6.8)1.3%—Phpkobo Address Book Script3/23/20106/16/2026
Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter. NOTE: the provenance of this information is unknown;…
ModifiedMedium (6.8)2.3%💥 ExploitPhpkobo Address Book Script3/23/20106/16/2026
Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter.
ModifiedMedium (6.8)0.91%💥 ExploitChatelao PHP Address Book7/27/20096/16/2026
Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.
ModifiedMedium (6.8)4.1%💥 ExploitStudiolounge Address Book4/29/20096/16/2026
Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in profiles/.
ModifiedHigh (7.5)1.9%💥 ExploitPhp-address Book6/6/20086/16/2026
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) edit.php. NOTE: it was later reported that 4.0.x is also affected.
ModifiedMedium (4.3)1.5%💥 ExploitPhp-address Book6/6/20086/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI.
ModifiedHigh (9.3)7.8%💥 ExploitJoomla NFN Address BookMambo NFN Address Book3/22/20076/16/2026
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2)…
ModifiedMedium (6.4)15%—Zephyrsoft Toolbox Address Book Continued2/27/20076/16/2026
Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 and 1.01 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php, a variant of a SQL injection issue that was…
ModifiedMedium (6.4)1.1%—Zephyrsoft Toolbox Address Book Continued2/27/20076/16/2026
Multiple SQL injection vulnerabilities in Mathis Dirksen-Thedens ZephyrSoft Toolbox Address Book Continued (ABC) 1.00 allow remote attackers to execute arbitrary SQL commands via the id parameter to the (1) updateRow and (2) deleteRow functions in functions.php. NOTE: some of these details are obtained from third…
ModifiedMedium (5)1.8%—THE Address Book12/31/20066/16/2026
Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote attackers to include arbitrary files via a .. (dot dot) in the language parameter.
ModifiedMedium (5)1.3%—THE Address Book12/31/20066/16/2026
Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demonstrated by deleting arbitrary users via the id parameter in a deleteuser action in users.php.
Orbitaley — Vulnerabilities