Refbase
9 CVEs tracked since 2015. Since Sep 2015, none of them reached CISA KEV.
Refbase CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2015-09 | 9 | 0 |
Products
The products that kept showing up in Refbase's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 10 most recently published vulnerabilities affecting Refbase.
- CVE-2015-6010Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remote attackers to inject arbitrary web script o...4.3
- CVE-2015-6012Multiple open redirect vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remote attackers to redirect users to arbitrary web sites and ...5.8
- CVE-2015-6007Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to hijack the authentication of arbitrary users.6.8
- CVE-2015-6008install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword parameter, a different issue than CVE-2015-7381.7.5
- CVE-2015-6011Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allows remote attackers to conduct XML injection attacks via (1) the id parameter to unapi.php or (2) the styl...5.0
- CVE-2015-6009Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) t...7.5
- CVE-2015-7383Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge through 2015-04-28 allow remote attackers to inject arbitrary web script ...4.3
- CVE-2015-7382SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary SQL commands via the defaultCharacterSet parameter, a d...7.5
- CVE-2015-7381Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary PHP code via the (1) pathToMYSQL ...7.5
- CVE-2008-6400Cross-site scripting (XSS) vulnerability in refbase before 0.9.5 allows remote attackers to inject arbitrary web script or HTML via the headerMsg parameter to (1) show.php and (2) search.php. NOTE...4.3
The record
- Peak rank
- #10 in Sep 2015
- Busiest month shown
- Sep 2015, 9 CVEs
- Months with a KEV entry
- 0 since Sep 2015
- Monthly snapshots
- 1 since 2015