Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

308 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)14%—Logrocket-oauth2-example Project Logrocket-oauth2-example14/12/202217/6/2026
logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.
ModificadaMedia (5.4)0.42%—Tomexam5/12/202217/6/2026
Cross Site Scripting (XSS) vulnerability in TomExam 3.0 via p_name parameter to list.thtml.
ModificadaAlta (7.2)1.0%—Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System20/10/202217/6/2026
Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.
ModificadaMedia (5.4)0.50%—Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System20/10/202217/6/2026
Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List.
ModificadaAlta (8.8)0.52%—Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System20/10/202217/6/2026
Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.
ModificadaAlta (8.8)1.1%—Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System20/10/202217/6/2026
In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.
ModificadaMedia (6.5)0.62%—Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System20/10/202217/6/2026
In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.
ModificadaMedia (6.1)0.61%—Projectworlds Online Examination System14/10/202217/6/2026
Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.
ModificadaAlta (8.8)23%—Exam Reviewer Management System Project Exam Reviewer Management System27/9/202217/6/2026
In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).
ModificadaCrítica (9.8)1.3%—Exam Reviewer Management System Project Exam Reviewer Management System27/9/202217/6/2026
Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.
ModificadaCrítica (9.8)1.1%—Ethz Safe Exam Browser19/8/202217/6/2026
Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.
ModificadaCrítica (9.8)0.75%—Fabian Online Class AND Exam Scheduling System8/8/202217/6/2026
A vulnerability classified as critical was found in SourceCodester Online Class and Exam Scheduling System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/faculty_sched.php. The manipulation of the argument faculty with the input ' OR (SELECT 2078 FROM(SELECT…
ModificadaCrítica (9.8)0.75%—Fabian Online Class AND Exam Scheduling System8/8/202217/6/2026
A vulnerability classified as critical has been found in SourceCodester Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/class_sched.php. The manipulation of the argument class with the input '||(SELECT 0x684d6b6c WHERE 5993=5993 AND (SELECT 2096 FROM(SELECT…
ModificadaCrítica (9.8)1.6%—Projectworlds Online Examination System21/1/202217/6/2026
An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.
ModificadaMedia (6.1)0.94%—Tecnick Tcexam5/8/202117/6/2026
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if…
ModificadaMedia (6.1)0.95%—Tecnick Tcexam5/8/202117/6/2026
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by…
ModificadaAlta (7.5)6.0%💥 ExploitTecnick Tcexam30/7/202117/6/2026
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.
ModificadaMedia (5.3)1.3%—Tecnick Tcexam30/7/202117/6/2026
An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we would be presented with an ‘unknown email’ error. If an email is given that is registered with a user then this error will not appear. A…
ModificadaMedia (5.4)0.63%—Tecnick Tcexam30/7/202117/6/2026
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_select_mediafile.php could upload a malicious javascript payload which would be triggered when…
ModificadaMedia (5.4)0.61%—Tecnick Tcexam30/7/202117/6/2026
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_filemanager.php could upload a malicious javascript payload which would be triggered when another…
ModificadaMedia (6.1)0.69%—Online Examination System Project Online Examination System24/5/202117/6/2026
Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.
ModificadaMedia (6.5)0.66%—Online Examination System Project Online Examination System24/5/202117/6/2026
Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user.
ModificadaMedia (5.4)0.67%—Online Examination System Project Online Examination System9/12/202017/6/2026
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject or feedback parameter to feedback.php.
ModificadaMedia (6.1)0.69%—Online Examination System Project Online Examination System9/12/202017/6/2026
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the w parameter to index.php.
ModificadaMedia (6.1)0.70%—Online Examination System Project Online Examination System9/12/202017/6/2026
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the q parameter to feedback.php.
Orbitaley — Vulnerabilidades