Vulnerabilities

Summary — last 7 days

New vulnerabilities2,537▼ 356 vs. last week
Critical / high1,341▲ 75 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
–

8 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.1)0.65%—Tophub Toplist1/11/20206/17/2026
TopList before 2019-09-03 allows XSS via a title.
ModifiedHigh (7.5)1.1%—Nick Jones Topliste Module4/12/20076/16/2026
SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModifiedMedium (6.8)1.3%—Phpbb Toplist12/11/20066/16/2026
Cross-site scripting (XSS) vulnerability in toplist.php in PhpBB Toplist 1.3.7 allows remote attackers to inject arbitrary HTML or web script via the (1) Name and (2) Information fields when adding a new site (toplistnew action).
ModifiedLow (2.6)1.4%—Fire-mouse Toplist7/28/20066/16/2026
Cross-site scripting (XSS) vulnerability in add.php in Fire-Mouse Toplist 1.1 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the Seitenname parameter.
ModifiedMedium (5)1.2%—MT Orumcek Toplist7/13/20066/16/2026
MT Orumcek Toplist 2.2 stores DB/orumcektoplist.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.
ModifiedHigh (7.5)11%—Phpbb Group Phpbb Toplist5/3/20066/16/2026
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.
ModifiedMedium (6.4)2.0%—Phpbb Group Phpbb Toplist5/3/20066/16/2026
PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the returnpath parameter.
ModifiedHigh (7.5)1.2%—NootoplistAI9/21/20056/16/2026
SQL injection vulnerability in index.php in NooTopList 1.0.0 release 17 allows remote attackers to execute arbitrary SQL commands via the (1) o or (2) sort parameters.