Vulnerabilities
Summary — last 7 days
New vulnerabilities2,731▼ 12 vs. last week
Critical / high1,272▼ 242 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | High (8.7) | 0.96% | — | Sitemagic CMS | 12/17/2025 | 6/17/2026 | SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands. | |
| Modified | High (7.2) | 2.0% | — | Sitemagic CMS | 2/23/2019 | 6/17/2026 | An issue was discovered in Sitemagic CMS v4.4. In the index.php?SMExt=SMFiles URI, the user can upload a .php file to execute arbitrary code, as demonstrated by 404.php. This can only occur if the administrator neglects to set FileExtensionFilter and there are untrusted user accounts. NOTE: The maintainer states that… | |
| Modified | High (7.5) | 1.0% | 💥 Exploit | Emagic-cms Emagic Cms.net | 11/1/2007 | 6/16/2026 | SQL injection vulnerability in emc.asp in emagiC CMS.Net 4.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter. | |
| Modified | High (10) | 4.9% | 💥 Exploit | GEO Soft Magic CMS | 3/10/2007 | 6/16/2026 | PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. |