Vulnerabilities

Summary — last 7 days

New vulnerabilities3,006▼ 69 vs. last week
Critical / high1,420▲ 54 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)382▼ 128 vs. last week
–

5 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.3)0.36%—Rafymrx Toko-online-rotiAI7/16/20267/16/2026
A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipulation of the argument kd_cs leads to authorization bypass. The attack is possible to be carried out remotely. This product adopts a rolling…
DeferredMedium (6.9)0.65%—Rafymrx Toko-online-rotiAI7/12/20267/14/2026
A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery.…
DeferredMedium (5.5)0.41%—Rafymrx Toko-online-rotiAI7/12/20267/13/2026
A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this issue is some unknown functionality of the file proses/add.php. The manipulation of the argument kode_produk/kd_cs results in sql injection. The attack can be executed remotely. The exploit…
DeferredMedium (5.5)0.41%—Rafymrx Toko-online-rotiAI7/12/20267/15/2026
A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this vulnerability is an unknown functionality of the file proses/login.php. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The…
DeferredMedium (6.1)0.36%—Rafymrx Toko-online-rotiAI4/30/20266/17/2026
Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php component