Vulnerabilities
Summary — last 7 days
New vulnerabilities2,693▼ 76 vs. last week
Critical / high1,446▲ 304 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.7) | 0.64% | — | PhpuploaderAI | 6/29/2026 | 7/14/2026 | phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result… | |
| Modified | Medium (6.1) | 0.95% | — | Phpuploader Project Phpuploader | 2/24/2022 | 6/17/2026 | Cross-site scripting vulnerability in phpUploader v1.2 and earlier allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modified | High (7.5) | 1.7% | — | Phpuploader Project Phpuploader | 2/24/2022 | 6/17/2026 | SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the information in the database via unspecified vectors. |