Vulnerabilities

Summary — last 7 days

New vulnerabilities2,833▲ 192 vs. last week
Critical / high1,314▼ 122 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)250▲ 236 vs. last week
–

2 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (4.3)1.1%—Idevspot Idevcart12/28/20096/16/2026
Cross-site scripting (XSS) vulnerability in index.php in iDevCart 1.09 allows remote attackers to inject arbitrary web script or HTML via the SEARCH parameter in a browse action.
ModifiedMedium (6.8)2.0%💥 ExploitVisionburst Vcart1/16/20086/16/2026
PHP remote file inclusion vulnerability in VisionBurst vcart 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php and (2) checkout.php.
Orbitaley — Vulnerabilities