Vulnerabilities

Summary — last 7 days

New vulnerabilities3,001▼ 62 vs. last week
Critical / high1,373▲ 34 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)459▼ 50 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (4.3)1.6%—Garagesale Project Garagesale7/2/20146/17/2026
Cross-site scripting (XSS) vulnerability in templates/printAdminUsersList_Footer.tpl.php in the GarageSale plugin before 1.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.
ModifiedMedium (4.3)1.5%—Garagesalesjunkie Garagesales Script8/14/20096/16/2026
Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. NOTE: some of these details are obtained from third party information.
ModifiedHigh (7.5)2.0%—Garagesalesjunkie Garagesales Script8/14/20096/16/2026
SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL commands via the key parameter.