Vulnerabilities

Summary — last 7 days

New vulnerabilities2,731▲ 24 vs. last week
Critical / high1,467▲ 357 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)68▼ 458 vs. last week
–

5 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedHigh (8.8)0.25%—Salmen Simple Faucet Script11/12/20256/17/2026
A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admin.php?p=ads&c=1 allowing attackers to execute arbitrary code.
ModifiedHigh (7.5)0.95%—Faucet RYU8/11/20236/17/2026
An issue was discovered in OFPQueueGetConfigReply in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).
ModifiedHigh (7.5)0.95%—Faucet RYU8/11/20236/17/2026
An issue was discovered in OFPBundleCtrlMsg in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).
ModifiedMedium (5.4)0.30%—Bitcoin/altcoin Faucet Project Bitcoin/altcoin Faucet9/26/20226/17/2026
The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allowing attacker to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues
ModifiedMedium (5.4)0.29%—Simple Bitcoin Faucets Project Simple Bitcoin Faucets9/26/20226/17/2026
The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscribers to call it and add/delete/edit Bonds. Furthermore, due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting…