Vulnerabilities
Summary — last 7 days
New vulnerabilities2,537▼ 356 vs. last week
Critical / high1,341▲ 75 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
8 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.1) | 0.65% | — | Tophub Toplist | 1/11/2020 | 6/17/2026 | TopList before 2019-09-03 allows XSS via a title. | |
| Modified | High (7.5) | 1.1% | — | Nick Jones Topliste Module | 4/12/2007 | 6/16/2026 | SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modified | Medium (6.8) | 1.3% | — | Phpbb Toplist | 12/11/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in toplist.php in PhpBB Toplist 1.3.7 allows remote attackers to inject arbitrary HTML or web script via the (1) Name and (2) Information fields when adding a new site (toplistnew action). | |
| Modified | Low (2.6) | 1.4% | — | Fire-mouse Toplist | 7/28/2006 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in add.php in Fire-Mouse Toplist 1.1 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the Seitenname parameter. | |
| Modified | Medium (5) | 1.2% | — | MT Orumcek Toplist | 7/13/2006 | 6/16/2026 | MT Orumcek Toplist 2.2 stores DB/orumcektoplist.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request. | |
| Modified | High (7.5) | 11% | — | Phpbb Group Phpbb Toplist | 5/3/2006 | 6/16/2026 | PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter. | |
| Modified | Medium (6.4) | 2.0% | — | Phpbb Group Phpbb Toplist | 5/3/2006 | 6/16/2026 | PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the returnpath parameter. | |
| Modified | High (7.5) | 1.2% | — | NootoplistAI | 9/21/2005 | 6/16/2026 | SQL injection vulnerability in index.php in NooTopList 1.0.0 release 17 allows remote attackers to execute arbitrary SQL commands via the (1) o or (2) sort parameters. |