Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

496 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.78%—Demososo DM Enterprise Website Building System23/2/202417/6/2026
A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerability is the function dmlogin of the file indexDM_load.php of the component Cookie Handler. The manipulation of the argument is_admin with the input y leads to improper…
ModificadaAlta (7.5)0.68%—Website Builder BY Seedprod5/2/202417/6/2026
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprod_lite_new_lpage function in all versions up to, and including, 6.15.21. This makes it…
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaCrítica (9.8)0.67%—Kashipara Travel Website4/1/202417/6/2026
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaMedia (6.1)0.61%—Oretnom23 Simple Image Stack Website17/12/202317/6/2026
A vulnerability was found in SourceCodester Simple Image Stack Website 1.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument search with the input sy2ap%22%3e%3cscript%3ealert(1)%3c%2fscript%3etkxh1 leads to cross site scripting. The attack may be initiated…
ModificadaCrítica (9.8)1.0%—Cybrosys Website Blog Search15/12/202317/6/2026
A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component.
ModificadaMedia (5.4)25%—Elementor Website Builder30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4.
ModificadaCrítica (9.8)0.91%—Mizhexiaoxiao Websiteguide20/11/202317/6/2026
An Insecure Permissions issue in WebsiteGuide v.0.2 allows a remote attacker to gain escalated privileges via crafted jwt (JSON web token).
ModificadaMedia (4.8)0.39%—Northernbeacheswebsites Ideapush8/11/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson IdeaPush plugin <= 8.52 versions.
ModificadaAlta (7.2)0.79%—Company Website CMS Project Company Website CMS2/11/202317/6/2026
A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /dashboard/createblog of the component Create Blog Page. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit…
AnalizadaMedia (4.8)0.42%—Northernbeacheswebsites WP Gotowebinar25/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson WP GoToWebinar plugin <= 14.45 versions.
ModificadaMedia (4.3)0.32%—Website Builder BY Seedprod20/10/202317/6/2026
The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.15.13.1. This is due to missing or incorrect nonce validation on functionality in the builder.php file. This makes it possible for unauthenticated attackers to change the stripe connect…
ModificadaMedia (6.1)0.41%—Leaptodigital Contact Form Website TO Workflow Tool2/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Leap Contractor Contact Form Website to Workflow Tool plugin <= 4.0.0 versions.
ModificadaCrítica (9.8)0.74%—Food Ordering Website Project Food Ordering Website17/9/202317/6/2026
A vulnerability was found in Sakshi2610 Food Ordering Website 1.0 and classified as critical. This issue affects some unknown processing of the file categoryfood.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
ModificadaCrítica (9.8)7.9%💥 ExploitCampcodes Complete Online Matrimonial Website System Script16/8/202317/6/2026
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.
ModificadaMedia (6.1)3.4%💥 ExploitElementor Website Builder14/8/202317/6/2026
The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs.
ModificadaMedia (6.1)0.45%—Gzscripts Vacation Rental Website12/7/202317/6/2026
A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issue is some unknown functionality of the file /VacationRentalWebsite/property/8/ad-has-principes/ of the component HTTP POST Request Handler. The manipulation of the argument username/title/comment…
ModificadaCrítica (9.8)1.6%—Websiteguide Project Websiteguide11/7/202317/6/2026
WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.
ModificadaAlta (8.8)0.31%—Magenet Website Monetization10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in MageNet Website Monetization by MageNet plugin <= 1.0.29.1 versions.
ModificadaAlta (7.5)0.60%—Sanchitkmr Shopping Website7/7/202317/6/2026
A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file check_availability.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaAlta (8.8)0.94%—Sanchitkmr Shopping Website4/7/202317/6/2026
A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public…
Orbitaley — Vulnerabilidades