Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.34% | — | Hasthemes Preview Link Generator | 27/3/2023 | 17/6/2026 | The Preview Link Generator WordPress plugin before 1.0.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Media (6.1) | 0.39% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 23/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Automatic Question Paper Generator System 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_class. The manipulation of the argument description leads to cross site scripting. The attack may be… | |
| Modificada | Crítica (9.8) | 0.54% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 23/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file admin/courses/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be… | |
| Modificada | Crítica (9.8) | 0.54% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 23/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Automatic Question Paper Generator System 1.0. This affects an unknown part of the file classes/Users.php?f=save_ruser. The manipulation of the argument id/email leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.49% | — | Medical Certificate Generator APP Project Medical Certificate Generator APP | 22/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been declared as critical. This vulnerability affects unknown code of the file action.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.84% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 17/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file users/question_papers/manage_question_paper.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The… | |
| Modificada | Crítica (9.8) | 0.82% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 17/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/courses/view_course.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql… | |
| Modificada | Alta (8.8) | 0.78% | — | Automatic Question Paper Generator System Project Automatic Question Paper Generator System | 17/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Automatic Question Paper Generator System 1.0. Affected is an unknown function of the file users/user/manage_user.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to… | |
| Modificada | Alta (8.8) | 0.26% | — | Themeisle Multiple Page Generator | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG plugin <= 3.3.9 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Codeermeneer Companion Sitemap Generator | 13/3/2023 | 17/6/2026 | The Companion Sitemap Generator WordPress plugin through 4.5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (4.9) | 0.61% | — | Employee Payslip Generator System Project Employee Payslip Generator System | 12/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Employee Payslip Generator with Sending Mail 1.2.0 and classified as critical. This issue affects some unknown processing of the file classes/Users.php?f=save of the component New User Creation. The manipulation of the argument username leads to sql injection. The attack may… | |
| Modificada | Media (5.4) | 0.26% | — | Medical Certificate Generator APP Project Medical Certificate Generator APP | 24/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been classified as problematic. This affects an unknown part of the component New Record Handler. The manipulation of the argument Firstname/Middlename/Lastname/Suffix/Nationality/Doctor Fullname/Doctor Suffix with the input… | |
| Modificada | Media (6.1) | 0.53% | — | Generator-hottowel Project Generator-hottowel | 20/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in generator-hottowel 0.0.11. Affected is an unknown function of the file app/templates/src/server/_app.js of the component 404 Error Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the… | |
| Modificada | Alta (7.4) | 0.68% | — | Fujitsu Tsclinical Define.xml GeneratorFujitsu Tsclinical Metadata Desktop Tools | 15/2/2023 | 17/6/2026 | Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) and tsClinical Metadata Desktop Tools Version 1.0.3 to Version 1.1.0. If this vulnerability is exploited, an attacker may obtain an arbitrary file which meets a certain… | |
| Modificada | Crítica (9.8) | 0.52% | — | Medical Certificate Generator APP Project Medical Certificate Generator APP | 10/2/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Medical Certificate Generator App 1.0 and classified as critical. This vulnerability affects unknown code of the file action.php. The manipulation of the argument lastname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.31% | — | Medical Certificate Generator APP Project Medical Certificate Generator APP | 7/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been rated as critical. Affected by this issue is the function delete_record of the file function.php. The manipulation of the argument id leads to sql injection. VDB-220346 is the identifier assigned to this vulnerability. | |
| Modificada | Alta (8.8) | 0.31% | — | Medical Certificate Generator APP Project Medical Certificate Generator APP | 7/2/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Medical Certificate Generator App 1.0. Affected by this issue is some unknown functionality of the file manage_record.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The identifier… | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Wpswings PDF Generator FOR Wordpress | 6/2/2023 | 17/6/2026 | The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin | |
| Modificada | Alta (7.5) | 1.5% | 💥 PoC | QR Code Generator Project QR Code Generator | 25/7/2022 | 9/7/2026 | A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal. | |
| Modificada | Crítica (9.8) | 0.88% | — | Otp-generator Project Otp-generator | 25/7/2022 | 17/6/2026 | The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack. | |
| Modificada | Crítica (9.1) | 0.61% | — | Linuxfoundation Rocket Chip Generator | 18/7/2022 | 17/6/2026 | Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala. | |
| Modificada | Media (4.8) | 0.59% | — | Supsystic Data Tables Generator | 17/7/2022 | 17/6/2026 | The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.59% | — | Wpzinc Page Generator | 17/7/2022 | 17/6/2026 | The Page Generator WordPress plugin before 1.6.5 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Xmlsitemapgenerator XML Sitemap Generator | 23/5/2022 | 17/6/2026 | The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on. |