Vulnerabilities
Summary — last 7 days
New vulnerabilities2,837▲ 84 vs. last week
Critical / high1,317▼ 206 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 228 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.1) | 0.65% | — | Phpliteadmin | 3/13/2022 | 6/17/2026 | phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or number). | |
| Modified | Critical (9.8) | 1.5% | — | Phpliteadmin | 4/25/2018 | 6/17/2026 | An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in classes/Authorization.php for the user-provided login password, it is possible to login with a simpler password if the password has the form of a power in scientific notation (like '2e2' for '200' or… | |
| Modified | Medium (4.3) | 3.5% | 💥 Exploit | Phpliteadmin | 8/18/2015 | 6/17/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) droptable parameter, or (3) table parameter to phpliteadmin.php. | |
| Modified | Medium (6.8) | 2.6% | 💥 Exploit | Phpliteadmin Project Phpliteadmin | 8/18/2015 | 6/17/2026 | Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1 allows remote attackers to hijack the authentication of users for requests that drop database tables via the droptable parameter to phpliteadmin.php. |