Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.78% | — | Demososo DM Enterprise Website Building System | 23/2/2024 | 17/6/2026 | A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerability is the function dmlogin of the file indexDM_load.php of the component Cookie Handler. The manipulation of the argument is_admin with the input y leads to improper… | |
| Modificada | Alta (7.5) | 0.68% | — | Website Builder BY Seedprod | 5/2/2024 | 17/6/2026 | The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprod_lite_new_lpage function in all versions up to, and including, 6.15.21. This makes it… | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Travel Website | 4/1/2024 | 17/6/2026 | Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Media (6.1) | 0.61% | — | Oretnom23 Simple Image Stack Website | 17/12/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Image Stack Website 1.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the argument search with the input sy2ap%22%3e%3cscript%3ealert(1)%3c%2fscript%3etkxh1 leads to cross site scripting. The attack may be initiated… | |
| Modificada | Crítica (9.8) | 1.0% | — | Cybrosys Website Blog Search | 15/12/2023 | 17/6/2026 | A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component. | |
| Modificada | Media (5.4) | 25% | — | Elementor Website Builder | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor.Com Elementor allows Cross-Site Scripting (XSS).This issue affects Elementor: from n/a through 3.16.4. | |
| Modificada | Crítica (9.8) | 0.91% | — | Mizhexiaoxiao Websiteguide | 20/11/2023 | 17/6/2026 | An Insecure Permissions issue in WebsiteGuide v.0.2 allows a remote attacker to gain escalated privileges via crafted jwt (JSON web token). | |
| Modificada | Media (4.8) | 0.39% | — | Northernbeacheswebsites Ideapush | 8/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson IdeaPush plugin <= 8.52 versions. | |
| Modificada | Alta (7.2) | 0.79% | — | Company Website CMS Project Company Website CMS | 2/11/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /dashboard/createblog of the component Create Blog Page. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit… | |
| Analizada | Media (4.8) | 0.42% | — | Northernbeacheswebsites WP Gotowebinar | 25/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson WP GoToWebinar plugin <= 14.45 versions. | |
| Modificada | Media (4.3) | 0.32% | — | Website Builder BY Seedprod | 20/10/2023 | 17/6/2026 | The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.15.13.1. This is due to missing or incorrect nonce validation on functionality in the builder.php file. This makes it possible for unauthenticated attackers to change the stripe connect… | |
| Modificada | Media (6.1) | 0.41% | — | Leaptodigital Contact Form Website TO Workflow Tool | 2/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Leap Contractor Contact Form Website to Workflow Tool plugin <= 4.0.0 versions. | |
| Modificada | Crítica (9.8) | 0.74% | — | Food Ordering Website Project Food Ordering Website | 17/9/2023 | 17/6/2026 | A vulnerability was found in Sakshi2610 Food Ordering Website 1.0 and classified as critical. This issue affects some unknown processing of the file categoryfood.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Crítica (9.8) | 7.9% | 💥 Exploit | Campcodes Complete Online Matrimonial Website System Script | 16/8/2023 | 17/6/2026 | install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document. | |
| Modificada | Media (6.1) | 3.4% | 💥 Exploit | Elementor Website Builder | 14/8/2023 | 17/6/2026 | The Elementor Website Builder WordPress plugin before 3.5.5 does not filter out user-controlled URLs from being loaded into the DOM. This could be used to inject rogue iframes that point to malicious URLs. | |
| Modificada | Media (6.1) | 0.45% | — | Gzscripts Vacation Rental Website | 12/7/2023 | 17/6/2026 | A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issue is some unknown functionality of the file /VacationRentalWebsite/property/8/ad-has-principes/ of the component HTTP POST Request Handler. The manipulation of the argument username/title/comment… | |
| Modificada | Crítica (9.8) | 1.6% | — | Websiteguide Project Websiteguide | 11/7/2023 | 17/6/2026 | WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload. | |
| Modificada | Alta (8.8) | 0.31% | — | Magenet Website Monetization | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MageNet Website Monetization by MageNet plugin <= 1.0.29.1 versions. | |
| Modificada | Alta (7.5) | 0.60% | — | Sanchitkmr Shopping Website | 7/7/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file check_availability.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.94% | — | Sanchitkmr Shopping Website | 4/7/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public… |