Vulnerabilities
Summary — last 7 days
New vulnerabilities3,006▼ 69 vs. last week
Critical / high1,420▲ 54 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)382▼ 128 vs. last week
5 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.36% | — | Rafymrx Toko-online-rotiAI | 7/16/2026 | 7/16/2026 | A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipulation of the argument kd_cs leads to authorization bypass. The attack is possible to be carried out remotely. This product adopts a rolling… | |
| Deferred | Medium (6.9) | 0.65% | — | Rafymrx Toko-online-rotiAI | 7/12/2026 | 7/14/2026 | A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery.… | |
| Deferred | Medium (5.5) | 0.41% | — | Rafymrx Toko-online-rotiAI | 7/12/2026 | 7/13/2026 | A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this issue is some unknown functionality of the file proses/add.php. The manipulation of the argument kode_produk/kd_cs results in sql injection. The attack can be executed remotely. The exploit… | |
| Deferred | Medium (5.5) | 0.41% | — | Rafymrx Toko-online-rotiAI | 7/12/2026 | 7/15/2026 | A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this vulnerability is an unknown functionality of the file proses/login.php. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The… | |
| Deferred | Medium (6.1) | 0.36% | — | Rafymrx Toko-online-rotiAI | 4/30/2026 | 6/17/2026 | Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php component |