Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3004 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.35% | — | Erponline ERP OnlineAI | 20/4/2026 | 17/6/2026 | A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipulation of the argument Item Name results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public… | |
| Aplazada | Media (4.3) | 0.11% | — | Zaytech Smart Online Order FOR CloverAI | 15/4/2026 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.1) | 0.53% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/4/2026 | 17/6/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/attendance_list.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_department.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/manage_employee.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_employee.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Employees Work From Home Attendance SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_attendance/admin/view_att.php. | |
| Aplazada | Alta (8.8) | 0.30% | — | Phpgurukul Online Course RegistrationAI | 13/4/2026 | 17/6/2026 | In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my-profile.php page. | |
| Aplazada | Baja (2.1) | 0.38% | 💥 PoC | Codeastro Online JOB PortalAI | 13/4/2026 | 17/6/2026 | A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of the component Delete Job Posting Handler. Such manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit is… | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Thesis Archiving SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/manage_curriculum.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Thesis Archiving SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php. | |
| Aplazada | Alta (7.3) | 0.29% | — | Sourcecodester Online Thesis Archiving SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Resort Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/rooms/view_room.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Resort Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in /orms/admin/reservations/view_details.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Resort Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/manage_activity.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Online Resort Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_room.php. | |
| Analizada | Baja (2.7) | 0.32% | — | Janobe Online Reviewer System | 13/4/2026 | 17/6/2026 | Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php. | |
| Analizada | Baja (2.7) | 0.32% | — | Janobe Online Reviewer System | 13/4/2026 | 17/6/2026 | Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php. | |
| Analizada | Crítica (9.8) | 0.50% | — | Janobe Engineers Online Portal | 10/4/2026 | 17/6/2026 | SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter. | |
| Analizada | Crítica (9.8) | 0.50% | — | Itsourcecode Online Student Enrollment System | 10/4/2026 | 17/6/2026 | A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation. |