Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
308 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.67% | — | Projectworlds Online Examination System | 21/12/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the /update.php?q=addqns resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Media (5.3) | 0.53% | — | Kaoshifeng Yunfan Learning Examination System | 4/11/2023 | 17/6/2026 | An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password parameter in the login function. | |
| Modificada | Crítica (9.8) | 0.70% | — | Online Examination System Project Online Examination System | 2/11/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'email' parameter of the feed.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Media (6.1) | 0.41% | — | Projectworlds Online Examination System | 1/11/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | |
| Modificada | Media (6.1) | 0.41% | — | Projectworlds Online Examination System | 1/11/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | |
| Modificada | Media (6.1) | 0.39% | — | Projectworlds Online Examination System | 1/11/2023 | 17/6/2026 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | |
| Modificada | Crítica (9.8) | 0.98% | — | Exam Form Submission IN PHP With Source Code Project Exam Form Submission IN PHP With Source Code | 18/9/2023 | 17/6/2026 | SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php. | |
| Modificada | Crítica (9.8) | 0.52% | 💥 PoC | Digiexam | 12/7/2023 | 9/7/2026 | DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers. | |
| Modificada | Alta (8.8) | 0.26% | — | Wepupil Quiz Expert - Easy Quiz Maker, Exam AND Test Manager | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WePupil Quiz Expert plugin <= 1.5.0 versions. | |
| Modificada | Media (6.5) | 0.38% | — | Online Examination System Project Online Examination System | 7/7/2023 | 17/6/2026 | The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin user, will delete a user account from the database without the admin's consent. The email of the user to be deleted is passed as a… | |
| Modificada | Crítica (9.8) | 0.74% | — | Online Exam Form Submission Project Online Exam Form Submission | 2/6/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /admin/update_s6.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Alta (8.8) | 0.73% | — | Online Exam System Project Online Exam System | 17/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Exam System 1.0. This issue affects some unknown processing of the file /jurusanmatkul/data. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 0.73% | — | Online Exam System Project Online Exam System | 17/5/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Exam System 1.0. This vulnerability affects unknown code of the file /kelasdosen/data. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /jurusan/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /matkul/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be initiated remotely.… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /kelas/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack can be initiated remotely.… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0. It has been classified as critical. This affects an unknown part of the file /dosen/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. It is possible to initiate the attack remotely.… | |
| Modificada | Crítica (9.8) | 0.82% | — | Online Exam System Project Online Exam System | 14/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Exam System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /mahasiswa/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be launched… | |
| Modificada | Crítica (9.8) | 0.73% | — | Online Exam System Project Online Exam System | 11/5/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. This affects an unknown part of the file adminpanel/admin/facebox_modal/updateCourse.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the… | |
| Modificada | Media (6.5) | 0.23% | — | Online Exam Software \ Eexamhall Project | 20/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Aarvanshinfotech Online Exam Software: eExamhall plugin <= 4.0 versions. | |
| Modificada | Crítica (9.8) | 1.4% | — | Yf-exam Project Yf-exam | 3/3/2023 | 17/6/2026 | CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE). | |
| Modificada | Alta (7.5) | 0.65% | — | Yf-exam Project Yf-exam | 3/3/2023 | 17/6/2026 | CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A token can be forged with his username to bypass authentication. | |
| Modificada | Alta (7.5) | 0.59% | — | Yf-exam Project Yf-exam | 3/3/2023 | 17/6/2026 | CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, resulting in any file upload. | |
| Modificada | Crítica (9.8) | 0.78% | — | Yf-exam Project Yf-exam | 2/3/2023 | 17/6/2026 | CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection. | |
| Modificada | Alta (8.8) | 0.79% | — | Class AND Exam Timetabling System Project Class AND Exam Timetabling System | 26/2/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index3.php of the component POST Parameter Handler. The manipulation of the argument password leads to sql injection. The attack can be… |