Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
308 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 14% | — | Logrocket-oauth2-example Project Logrocket-oauth2-example | 14/12/2022 | 17/6/2026 | logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter. | |
| Modificada | Media (5.4) | 0.42% | — | Tomexam | 5/12/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in TomExam 3.0 via p_name parameter to list.thtml. | |
| Modificada | Alta (7.2) | 1.0% | — | Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System | 20/10/2022 | 17/6/2026 | Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload. | |
| Modificada | Media (5.4) | 0.50% | — | Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System | 20/10/2022 | 17/6/2026 | Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List. | |
| Modificada | Alta (8.8) | 0.52% | — | Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System | 20/10/2022 | 17/6/2026 | Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List. | |
| Modificada | Alta (8.8) | 1.1% | — | Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System | 20/10/2022 | 17/6/2026 | In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload. | |
| Modificada | Media (6.5) | 0.62% | — | Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System | 20/10/2022 | 17/6/2026 | In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges. | |
| Modificada | Media (6.1) | 0.61% | — | Projectworlds Online Examination System | 14/10/2022 | 17/6/2026 | Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php. | |
| Modificada | Alta (8.8) | 23% | — | Exam Reviewer Management System Project Exam Reviewer Management System | 27/9/2022 | 17/6/2026 | In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE). | |
| Modificada | Crítica (9.8) | 1.3% | — | Exam Reviewer Management System Project Exam Reviewer Management System | 27/9/2022 | 17/6/2026 | Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter. | |
| Modificada | Crítica (9.8) | 1.1% | — | Ethz Safe Exam Browser | 19/8/2022 | 17/6/2026 | Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog. | |
| Modificada | Crítica (9.8) | 0.75% | — | Fabian Online Class AND Exam Scheduling System | 8/8/2022 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Class and Exam Scheduling System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/faculty_sched.php. The manipulation of the argument faculty with the input ' OR (SELECT 2078 FROM(SELECT… | |
| Modificada | Crítica (9.8) | 0.75% | — | Fabian Online Class AND Exam Scheduling System | 8/8/2022 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/class_sched.php. The manipulation of the argument class with the input '||(SELECT 0x684d6b6c WHERE 5993=5993 AND (SELECT 2096 FROM(SELECT… | |
| Modificada | Crítica (9.8) | 1.6% | — | Projectworlds Online Examination System | 21/1/2022 | 17/6/2026 | An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php. | |
| Modificada | Media (6.1) | 0.94% | — | Tecnick Tcexam | 5/8/2021 | 17/6/2026 | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if… | |
| Modificada | Media (6.1) | 0.95% | — | Tecnick Tcexam | 5/8/2021 | 17/6/2026 | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by… | |
| Modificada | Alta (7.5) | 6.0% | 💥 Exploit | Tecnick Tcexam | 30/7/2021 | 17/6/2026 | When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files. | |
| Modificada | Media (5.3) | 1.3% | — | Tecnick Tcexam | 30/7/2021 | 17/6/2026 | An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for an email address that was not registered with a user then we would be presented with an ‘unknown email’ error. If an email is given that is registered with a user then this error will not appear. A… | |
| Modificada | Media (5.4) | 0.63% | — | Tecnick Tcexam | 30/7/2021 | 17/6/2026 | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_select_mediafile.php could upload a malicious javascript payload which would be triggered when… | |
| Modificada | Media (5.4) | 0.61% | — | Tecnick Tcexam | 30/7/2021 | 17/6/2026 | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_filemanager.php could upload a malicious javascript payload which would be triggered when another… | |
| Modificada | Media (6.1) | 0.69% | — | Online Examination System Project Online Examination System | 24/5/2021 | 17/6/2026 | Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php. | |
| Modificada | Media (6.5) | 0.66% | — | Online Examination System Project Online Examination System | 24/5/2021 | 17/6/2026 | Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user. | |
| Modificada | Media (5.4) | 0.67% | — | Online Examination System Project Online Examination System | 9/12/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject or feedback parameter to feedback.php. | |
| Modificada | Media (6.1) | 0.69% | — | Online Examination System Project Online Examination System | 9/12/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the w parameter to index.php. | |
| Modificada | Media (6.1) | 0.70% | — | Online Examination System Project Online Examination System | 9/12/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the q parameter to feedback.php. |