Vulnerabilities
Summary — last 7 days
New vulnerabilities2,666▼ 407 vs. last week
Critical / high1,266▼ 215 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)215▼ 115 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (4.3) | 1.0% | — | Thomas Mammitzsch VX Xajax Shoutbox | 10/9/2011 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in the xaJax Shoutbox (vx_xajax_shoutbox) extension before 1.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modified | Medium (5) | 1.3% | — | Xajax-project Xajax | 9/24/2011 | 6/16/2026 | xajax 0.6 beta1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xajax_core/plugin_layer/xajaxScriptPlugin.inc.php and certain other files. | |
| Modified | Medium (4.3) | 1.3% | — | Xajax | 5/17/2007 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in xajax before 0.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modified | Medium (6.8) | 1.0% | — | Xajax | 5/17/2007 | 6/16/2026 | Unspecified vulnerability in xajax before 0.2.5 has unknown impact and attack vectors, not related to XSS. |