Vulnerabilities
Summary — last 7 days
New vulnerabilities2,698▼ 546 vs. last week
Critical / high1,273▼ 220 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)254▼ 248 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (4.3) | 1.4% | 💥 Exploit | Giombetti Phppowercards | 12/30/2009 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in pagenumber.inc.php in phpPowerCards 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, the (2) archiv parameter, and the (3) subcat parameter. | |
| Modified | Low (2.6) | 2.6% | 💥 Exploit | Marc Giombetti Phppowercards | 10/20/2006 | 6/16/2026 | Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) email[from], (3) name[to], (4) name[from], (5) picture, (6) comment, or (7) sessionID parameter, as… |