Vulnerabilities

Summary — last 7 days

New vulnerabilities3,064▲ 586 vs. last week
Critical / high1,461▲ 295 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)382▲ 175 vs. last week
–

8 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredCritical (9.8)0.65%—Baptiste Gourdin TalkbackAI10/11/20246/17/2026
Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue affects Talkback: from n/a through <= 1.0.
ModifiedMedium (6.4)2.6%—Scripts.oldguy Talkback5/26/20106/16/2026
TalkBack 2.3.14 does not properly restrict access to the edit comment feature (comments.php), which allows remote attackers to modify comments.
ModifiedHigh (7.5)3.1%—Scripts.oldguy Talkback5/7/20106/16/2026
addons/import.php in TalkBack 2.3.14 allows remote attackers to execute arbitrary commands via the result parameter.
ModifiedHigh (7.5)2.8%—Talkback9/30/20086/16/2026
Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to comments.php, a different vector than CVE-2008-3371.
ModifiedMedium (5)2.6%—Talkback9/16/20086/16/2026
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.
ModifiedHigh (7.5)3.5%—Talkback7/30/20086/16/2026
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.
ModifiedMedium (6.8)6.7%—Talkback11/23/20076/16/2026
Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) language_file parameter to (a) comments-display-tpl.php and (b) addons/separate-comments-mod/my-comments-display-tpl.php and the (2) config[comments_form_tpl] parameter to…
ModifiedMedium (5)3.4%—WAY TO THE WEB Talkback6/18/20016/16/2026
Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.