Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3004 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (1.9)0.35%—Erponline ERP OnlineAI20/4/202617/6/2026
A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipulation of the argument Item Name results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public…
AplazadaMedia (4.3)0.11%—Zaytech Smart Online Order FOR CloverAI15/4/20267/10/2026
Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/4/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/4/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/4/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/4/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.1)0.53%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/4/202617/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/attendance_list.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Employees Work From Home Attendance SystemAI14/4/202617/6/2026
SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php.
AplazadaAlta (8.8)0.30%—Phpgurukul Online Course RegistrationAI13/4/202617/6/2026
In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my-profile.php page.
AplazadaBaja (2.1)0.38%💥 PoCCodeastro Online JOB PortalAI13/4/202617/6/2026
A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of the component Delete Job Posting Handler. Such manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit is…
AplazadaBaja (2.7)0.31%—Sourcecodester Online Thesis Archiving SystemAI13/4/202617/6/2026
Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/manage_curriculum.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Thesis Archiving SystemAI13/4/202617/6/2026
Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php.
AplazadaAlta (7.3)0.29%—Sourcecodester Online Thesis Archiving SystemAI13/4/202617/6/2026
Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Resort Management SystemAI13/4/202617/6/2026
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Resort Management SystemAI13/4/202617/6/2026
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_details.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Resort Management SystemAI13/4/202617/6/2026
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/manage_activity.php.
AplazadaBaja (2.7)0.31%—Sourcecodester Online Resort Management SystemAI13/4/202617/6/2026
Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_room.php.
AnalizadaBaja (2.7)0.32%—Janobe Online Reviewer System13/4/202617/6/2026
Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php.
AnalizadaBaja (2.7)0.32%—Janobe Online Reviewer System13/4/202617/6/2026
Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php.
AnalizadaCrítica (9.8)0.50%—Janobe Engineers Online Portal10/4/202617/6/2026
SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.
AnalizadaCrítica (9.8)0.50%—Itsourcecode Online Student Enrollment System10/4/202617/6/2026
A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation.