Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

496 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.65%—Sanchitkmr Shopping Website4/7/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Shopping Website 1.0. Affected is an unknown function of the file search-result.php. The manipulation of the argument product leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
ModificadaCrítica (9.1)0.58%—Kingstemple THE King's Temple Church Website3/7/202317/6/2026
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed and subsequently exposed in the codebase. If an unauthorized party gains access to…
ModificadaMedia (4.3)0.39%—Websitescanner Remove Schema1/7/202317/6/2026
The Remove Schema plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the validate() function. This makes it possible for unauthenticated attackers to modify the plugins settings via a forged request granted…
ModificadaCrítica (9.8)0.87%—Sanchitkmr Shopping Website29/6/202317/6/2026
A vulnerability was found in SourceCodester Shopping Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file forgot-password.php. The manipulation of the argument contact leads to sql injection. The attack can be launched remotely. The exploit has been…
ModificadaCrítica (9.8)0.87%—Sanchitkmr Shopping Website29/6/202317/6/2026
A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
ModificadaMedia (4.8)0.37%—Onewebsite WP Repost22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in OneWebsite WP Repost plugin <= 0.1 versions.
ModificadaMedia (4.8)0.73%—Visualcomposer Visual Composer Website Builder7/6/202317/6/2026
The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
ModificadaMedia (5.4)0.48%—Elementor Website Builder7/6/202317/6/2026
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user…
ModificadaAlta (7.2)20%—Elementor Website Builder30/5/202317/6/2026
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
ModificadaMedia (4.8)0.58%—Simple Mobile Comparison Website Project Simple Mobile Comparison Website28/4/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Mobile Comparison Website 1.0. This issue affects some unknown processing of the file classes/Master.php?f=save_field. The manipulation of the argument Field Name leads to cross site scripting. The attack may be initiated…
ModificadaAlta (7.5)0.60%—Campcodes Video Sharing Website Project Campcodes Video Sharing Website14/4/202317/6/2026
A vulnerability was found in Campcodes Video Sharing Website 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin_class.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and…
ModificadaCrítica (9.8)0.79%—Campcodes Video Sharing Website Project Campcodes Video Sharing Website14/4/202317/6/2026
A vulnerability was found in Campcodes Video Sharing Website 1.0. It has been classified as critical. This affects an unknown part of the file watch.php. The manipulation of the argument code leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.5)0.65%—Campcodes Video Sharing Website Project Campcodes Video Sharing Website14/4/202317/6/2026
A vulnerability was found in Campcodes Video Sharing Website 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file upload.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may…
ModificadaAlta (7.5)0.66%—Campcodes Video Sharing Website Project Campcodes Video Sharing Website14/4/202317/6/2026
A vulnerability has been found in Campcodes Video Sharing Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file signup.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.74%—Simple Mobile Comparison Website Project Simple Mobile Comparison Website6/4/202317/6/2026
A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/categories/view_category.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to…
ModificadaCrítica (9.8)0.73%—Simple Mobile Comparison Website Project Simple Mobile Comparison Website2/4/202317/6/2026
A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/fields/manage_field.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may…
ModificadaMedia (6.1)0.58%—Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System15/3/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file cashconfirm.php of the component POST Parameter Handler. The manipulation of the argument transactioncode leads to cross…
ModificadaCrítica (9.8)0.76%—Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System15/3/202317/6/2026
A vulnerability was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file addmem.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to sql injection. The attack may…
ModificadaCrítica (9.8)0.74%—Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System13/3/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. This vulnerability affects unknown code of the file paypalsuccess.php of the component POST Parameter Handler. The manipulation of the argument cusid leads to sql injection. The attack can be…
ModificadaCrítica (9.8)0.79%—Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System10/3/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. This affects an unknown part of the file large.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the…
ModificadaCrítica (9.8)0.79%—Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System9/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. Affected by this issue is some unknown functionality of the file deleteorder.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection.…
ModificadaMedia (6.1)0.54%—Oretnom23 Simple Responsive Tourism Website26/2/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Responsive Tourism Website 1.0. This affects an unknown part of the file /tourism/rate_review.php. The manipulation of the argument id with the input 1"><script>alert(1111)</script> leads to cross site scripting. It is possible to…
ModificadaCrítica (9.8)0.87%—Institutional Management Website Project Institutional Management Website8/2/202317/6/2026
File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.
ModificadaCrítica (9.8)0.95%—Institutional Management Website Project Institutional Management Website8/2/202317/6/2026
SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.
ModificadaAlta (8.8)0.66%—Challenge Website Project Challenge Website28/12/202217/6/2026
A vulnerability was found in challenge website. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. The name of the patch is f1644b1d3502e5aa5284f31ea80d2623817f4d42. It is recommended to apply a patch to fix this issue. The identifier VDB-216989 was…