Vulnerabilities

Summary — last 7 days

New vulnerabilities2,680▼ 660 vs. last week
Critical / high1,277▼ 279 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)228▼ 274 vs. last week
–

5 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (8.8)0.65%—Phpcoo Oecms7/18/20196/17/2026
OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator account. The component is: admincp.php. The attack vector is: network connectivity. The fixed version is: v4.3.
ModifiedMedium (5.4)5.6%💥 ExploitOecms Project Oecms6/11/20186/17/2026
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.
ModifiedMedium (5.8)1.1%—Foecms7/10/20146/17/2026
Open redirect vulnerability in msg.php in FoeCMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the r parameter.
ModifiedHigh (7.5)1.3%—Foecms7/10/20146/17/2026
SQL injection vulnerability in index.php in FoeCMS allows remote attackers to execute arbitrary SQL commands via the i parameter.
ModifiedMedium (4.3)0.99%—Foecms7/10/20146/17/2026
Multiple cross-site scripting (XSS) vulnerabilities in msg.php in FoeCMS allow remote attackers to inject arbitrary web script or HTML via the (1) e or (2) r parameter.
Orbitaley — Vulnerabilities