Vulnerabilities

Summary — last 7 days

New vulnerabilities2,684▼ 86 vs. last week
Critical / high1,444▲ 301 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
–

2 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (10)3.5%—Uploadscript UploadimageUploadscript1/12/20086/16/2026
admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.
ModifiedHigh (7.5)2.3%—Uploadscript UploadimageUploadscript1/12/20086/16/2026
admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.