Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

322 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.34%—Hasthemes Preview Link Generator27/3/202317/6/2026
The Preview Link Generator WordPress plugin before 1.0.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaMedia (6.1)0.39%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System23/3/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Automatic Question Paper Generator System 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_class. The manipulation of the argument description leads to cross site scripting. The attack may be…
ModificadaCrítica (9.8)0.54%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System23/3/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file admin/courses/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be…
ModificadaCrítica (9.8)0.54%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System23/3/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Automatic Question Paper Generator System 1.0. This affects an unknown part of the file classes/Users.php?f=save_ruser. The manipulation of the argument id/email leads to sql injection. It is possible to initiate the attack remotely. The…
ModificadaCrítica (9.8)0.49%—Medical Certificate Generator APP Project Medical Certificate Generator APP22/3/202317/6/2026
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been declared as critical. This vulnerability affects unknown code of the file action.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.84%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System17/3/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file users/question_papers/manage_question_paper.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The…
ModificadaCrítica (9.8)0.82%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System17/3/202317/6/2026
A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/courses/view_course.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql…
ModificadaAlta (8.8)0.78%—Automatic Question Paper Generator System Project Automatic Question Paper Generator System17/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Automatic Question Paper Generator System 1.0. Affected is an unknown function of the file users/user/manage_user.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to…
ModificadaAlta (8.8)0.26%—Themeisle Multiple Page Generator14/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG plugin <= 3.3.9 versions.
ModificadaMedia (5.4)0.44%—Codeermeneer Companion Sitemap Generator13/3/202317/6/2026
The Companion Sitemap Generator WordPress plugin through 4.5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (4.9)0.61%—Employee Payslip Generator System Project Employee Payslip Generator System12/3/202317/6/2026
A vulnerability was found in SourceCodester Employee Payslip Generator with Sending Mail 1.2.0 and classified as critical. This issue affects some unknown processing of the file classes/Users.php?f=save of the component New User Creation. The manipulation of the argument username leads to sql injection. The attack may…
ModificadaMedia (5.4)0.26%—Medical Certificate Generator APP Project Medical Certificate Generator APP24/2/202317/6/2026
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been classified as problematic. This affects an unknown part of the component New Record Handler. The manipulation of the argument Firstname/Middlename/Lastname/Suffix/Nationality/Doctor Fullname/Doctor Suffix with the input…
ModificadaMedia (6.1)0.53%—Generator-hottowel Project Generator-hottowel20/2/202317/6/2026
A vulnerability, which was classified as problematic, was found in generator-hottowel 0.0.11. Affected is an unknown function of the file app/templates/src/server/_app.js of the component 404 Error Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the…
ModificadaAlta (7.4)0.68%—Fujitsu Tsclinical Define.xml GeneratorFujitsu Tsclinical Metadata Desktop Tools15/2/202317/6/2026
Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) and tsClinical Metadata Desktop Tools Version 1.0.3 to Version 1.1.0. If this vulnerability is exploited, an attacker may obtain an arbitrary file which meets a certain…
ModificadaCrítica (9.8)0.52%—Medical Certificate Generator APP Project Medical Certificate Generator APP10/2/202317/6/2026
A vulnerability has been found in SourceCodester Medical Certificate Generator App 1.0 and classified as critical. This vulnerability affects unknown code of the file action.php. The manipulation of the argument lastname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.31%—Medical Certificate Generator APP Project Medical Certificate Generator APP7/2/202317/6/2026
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been rated as critical. Affected by this issue is the function delete_record of the file function.php. The manipulation of the argument id leads to sql injection. VDB-220346 is the identifier assigned to this vulnerability.
ModificadaAlta (8.8)0.31%—Medical Certificate Generator APP Project Medical Certificate Generator APP7/2/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Medical Certificate Generator App 1.0. Affected by this issue is some unknown functionality of the file manage_record.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The identifier…
ModificadaMedia (6.1)1.2%💥 ExploitWpswings PDF Generator FOR Wordpress6/2/202317/6/2026
The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin
ModificadaAlta (7.5)1.5%💥 PoCQR Code Generator Project QR Code Generator25/7/20229/7/2026
A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.
ModificadaCrítica (9.8)0.88%—Otp-generator Project Otp-generator25/7/202217/6/2026
The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.
ModificadaCrítica (9.1)0.61%—Linuxfoundation Rocket Chip Generator18/7/202217/6/2026
Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala.
ModificadaMedia (4.8)0.59%—Supsystic Data Tables Generator17/7/202217/6/2026
The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (4.8)0.59%—Wpzinc Page Generator17/7/202217/6/2026
The Page Generator WordPress plugin before 1.6.5 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaMedia (6.1)2.1%💥 ExploitXmlsitemapgenerator XML Sitemap Generator23/5/202217/6/2026
The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.
Orbitaley — Vulnerabilidades