Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2095 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.56% | — | NodemailerRedhat Advanced Cluster Management FOR KubernetesRedhat Ceph StorageRedhat Developer HUB | 18/12/2025 | 7/10/2026 | A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser. | |
| Modificada | Media (5.5) | 0.39% | — | Campcodes Advanced Online Examination System | 14/12/2025 | 28/9/2026 | A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Analizada | Alta (8.7) | 0.56% | — | Puneethreddyhc Online Shopping System Advanced | 12/12/2025 | 17/6/2026 | Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by… | |
| Analizada | Media (5.5) | 0.43% | — | Projectworlds Advanced Library Management System | 12/12/2025 | 7/10/2026 | A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /borrow_book.php. Such manipulation of the argument roll_number leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.43% | — | Projectworlds Advanced Library Management System | 12/12/2025 | 7/10/2026 | A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_admin.php. This manipulation of the argument admin_id causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Modificada | Media (5.5) | 0.39% | — | Projectworlds Advanced Library Management System | 11/12/2025 | 7/10/2026 | A weakness has been identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /view_book.php. Executing a manipulation of the argument book_id can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public… | |
| Aplazada | Alta (8.5) | 0.12% | — | QND PremiumAIQND AdvanceAIQND StandardAI | 11/12/2025 | 17/6/2026 | QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system with the affected product to gain administrator privileges. As a result, sensitive information may be accessed or altered, and arbitrary actions may be performed. | |
| Aplazada | Media (4.3) | 0.15% | — | Advanced Product FieldsAI | 9/12/2025 | 17/6/2026 | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.17. This is due to missing or incorrect nonce validation on the 'maybe_duplicate' function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.9) | 0.21% | — | Themehigh Advanced FAQ ManagerAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHigh Advanced FAQ Manager advanced-faq-manager allows Stored XSS.This issue affects Advanced FAQ Manager: from n/a through <= 1.5.2. | |
| Aplazada | Media (6.5) | 0.20% | — | Themehigh Advanced FAQ ManagerAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHigh Advanced FAQ Manager advanced-faq-manager allows DOM-Based XSS.This issue affects Advanced FAQ Manager: from n/a through <= 1.5.2. | |
| Modificada | Media (5.5) | 0.39% | — | Projectworlds Advanced Library Management System | 8/12/2025 | 7/10/2026 | A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /member_search.php. Executing a manipulation of the argument roll_number can lead to sql injection. The attack may be launched remotely. The exploit has been published and may… | |
| Modificada | Media (5.5) | 0.39% | — | Projectworlds Advanced Library Management System | 8/12/2025 | 7/10/2026 | A vulnerability was detected in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_book.php. Performing a manipulation of the argument book_id results in sql injection. The attack may be initiated remotely. The exploit is now public and… | |
| Analizada | Media (5.5) | 0.39% | — | Projectworlds Advanced Library Management System | 8/12/2025 | 7/10/2026 | A security vulnerability has been detected in projectworlds Advanced Library Management System 1.0. Affected is an unknown function of the file /delete_member.php. Such manipulation of the argument user_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Crítica (9.8) | 68% | 💥 Exploit | Acfextended Advanced Custom Fields ExtendedAI | 3/12/2025 | 17/6/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated… | |
| Analizada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 24/11/2025 | 17/6/2026 | A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_book.php. The manipulation of the argument image results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may… | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Advanced Library Management System | 23/11/2025 | 17/6/2026 | A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /delete_admin.php. The manipulation of the argument admin_id leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 17/11/2025 | 7/10/2026 | A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrowed_book_search.php. Such manipulation of the argument datefrom/dateto leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Modificada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 17/11/2025 | 7/10/2026 | A weakness has been identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrow.php. Executing a manipulation of the argument roll_number can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the… | |
| Modificada | Baja (2.1) | 0.39% | — | Projectworlds Advanced Library Management System | 17/11/2025 | 7/10/2026 | A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. This issue affects some unknown processing of the file /book_search.php. Performing a manipulation of the argument book_pub/book_title results in sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 17/11/2025 | 7/10/2026 | A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /add_member.php. Such manipulation of the argument roll_number leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.35% | — | Projectworlds Advanced Library Management System | 16/11/2025 | 7/10/2026 | A vulnerability was determined in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /add_librarian.php. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Crítica (9.1) | 0.45% | — | Helmut Wandl Advanced SettingsAI | 6/11/2025 | 7/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Upload a Web Shell to a Web Server.This issue affects Advanced Settings: from n/a through <= 3.1.1. | |
| Aplazada | Alta (8.8) | 0.35% | — | Bplugins Advanced ScrollbarAI | 6/11/2025 | 7/10/2026 | Incorrect Privilege Assignment vulnerability in bPlugins Advanced scrollbar advanced-scrollbar allows Privilege Escalation.This issue affects Advanced scrollbar: from n/a through <= 1.1.8. | |
| Aplazada | Media (4.3) | 0.24% | — | Flippercode Advanced Google MapsAI | 6/11/2025 | 7/10/2026 | Missing Authorization vulnerability in flippercode Advanced Google Maps wp-google-map-gold allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Google Maps: from n/a through <= 5.8.4. | |
| Aplazada | Alta (7.3) | 0.47% | — | Advanced ADSAI | 1/11/2025 | 17/6/2026 | The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.12 via the select_one() function. This is due to the endpoint not properly restricting access to the AJAX endpoint or limiting the functions that can be called to safe… |