Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

496 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.49%—Ecommerce-website Project Ecommerce-website5/12/202217/6/2026
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.
ModificadaAlta (8.8)1.4%💥 PoCKlik-socialmediawebsite Project Klik-socialmediawebsite22/11/202217/6/2026
KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.
ModificadaCrítica (9.8)1.1%—Resumes Management AND JOB Application Website Application Project Resumes Management AND JOB Application Website Application27/9/202217/6/2026
SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application login form by EGavilan Media that allows authentication bypass through login.php.
ModificadaCrítica (9.8)2.7%—Simple College Website Project Simple College Website22/9/202217/6/2026
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.
ModificadaMedia (6.1)0.77%—Simple College Website Project Simple College Website22/9/202217/6/2026
Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_website/index.php?page=. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.
ModificadaCrítica (9.8)1.8%—Simple College Website Project Simple College Website22/9/202217/6/2026
Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (5.4)0.63%—Visualcomposer Visual Composer Website Builder6/9/202217/6/2026
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page 'Title' value in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer…
ModificadaMedia (5.4)0.63%—Visualcomposer Visual Composer Website Builder6/9/202217/6/2026
The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Block' feature in versions up to, and including, 45.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the visual composer…
ModificadaCrítica (9.8)22%—Sinsiu Enterprise Website System29/8/202217/6/2026
Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin.php?/deal/.
ModificadaMedia (5.4)0.60%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Company Website CMS. This issue affects some unknown processing of the file /dashboard/contact. The manipulation of the argument phone leads to cross site scripting. The attack may be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)1.2%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/settings. The manipulation leads to improper authentication. The attack can be launched remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be launched remotely. The identifier of this…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dashboard/add-service.php of the component Add Service Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-206022 is the…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the file /dashboard/add-blog.php of the component Add Blog. The manipulation of the argument ufile leads to unrestricted upload. The attack can be initiated remotely. VDB-205882…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashboard/updatelogo.php of the component Background Upload Logo Icon. The manipulation of the argument xfile/ufile leads to unrestricted upload. It is possible to initiate the…
ModificadaMedia (6.1)0.46%—Company Website CMS Project Company Website CMS9/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add-blog.php. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-205838 is the identifier assigned to this…
ModificadaMedia (6.1)1.7%💥 ExploitWrteam Eshop - Ecommerce / Store Website8/8/20228/7/2026
A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.
ModificadaCrítica (9.8)1.3%—Wpwhitesecurity Website File Changes Monitor8/8/202217/6/2026
The Website File Changes Monitor WordPress plugin before 1.8.3 does not sanitise and escape user input before using it in a SQL statement via an action available to users with the manage_options capability (by default admins), leading to an SQL injection
ModificadaMedia (6.5)0.63%—Company Website/cms Project Company Website/cms8/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file site-settings.php of the component Cookie Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been…
ModificadaAlta (8.8)0.85%—Company Website CMS Project Company Website CMS6/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205817 was…
ModificadaMedia (6.1)24%💥 ExploitElementor Website Builder13/6/202217/6/2026
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
ModificadaMedia (5.4)0.54%—Simple Food Website Project Simple Food Website23/5/202217/6/2026
In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0.1:1234/food/admin/all_users.php like Full Username, etc .This causes stored xss.
ModificadaAlta (8.8)0.55%—Simple Food Website Project Simple Food Website23/5/20229/7/2026
Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.
ModificadaMedia (5.4)0.56%—E-commerce Website Project E-commerce Website3/5/202217/6/2026
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Title text field.
ModificadaMedia (5.4)0.66%—Originprotocol Origin Website20/4/202217/6/2026
Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to `/presale/join`. User-controlled data is passed with no sanitization to SendGrid and injected into an email that is delivered to the…