Vulnerabilities
Summary — last 7 days
New vulnerabilities2,680▼ 660 vs. last week
Critical / high1,277▼ 279 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)228▼ 274 vs. last week
5 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (8.8) | 0.65% | — | Phpcoo Oecms | 7/18/2019 | 6/17/2026 | OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator account. The component is: admincp.php. The attack vector is: network connectivity. The fixed version is: v4.3. | |
| Modified | Medium (5.4) | 5.6% | 💥 Exploit | Oecms Project Oecms | 6/11/2018 | 6/17/2026 | A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php. | |
| Modified | Medium (5.8) | 1.1% | — | Foecms | 7/10/2014 | 6/17/2026 | Open redirect vulnerability in msg.php in FoeCMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the r parameter. | |
| Modified | High (7.5) | 1.3% | — | Foecms | 7/10/2014 | 6/17/2026 | SQL injection vulnerability in index.php in FoeCMS allows remote attackers to execute arbitrary SQL commands via the i parameter. | |
| Modified | Medium (4.3) | 0.99% | — | Foecms | 7/10/2014 | 6/17/2026 | Multiple cross-site scripting (XSS) vulnerabilities in msg.php in FoeCMS allow remote attackers to inject arbitrary web script or HTML via the (1) e or (2) r parameter. |