Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

496 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)93%💥 ExploitElementor Website Builder19/4/202217/6/2026
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to…
ModificadaCrítica (9.8)3.6%—Ecommerce-website Project Ecommerce-website8/4/202217/6/2026
Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (8.8)2.7%—Ecommerce-website Project Ecommerce-website8/4/202217/6/2026
Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (5.4)0.50%—College Website Content Management System Project College Website Content Management System5/4/202217/6/2026
A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields.
ModificadaMedia (4.8)0.99%—Ecommerce-website Project Ecommerce-website4/4/202217/6/2026
A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field.
ModificadaAlta (8.8)1.7%—Ecommerce-website Project Ecommerce-website4/4/202217/6/2026
An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.
ModificadaCrítica (9.8)0.80%—College Website Management System Project College Website Management System29/3/202217/6/2026
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input…
ModificadaMedia (5.4)0.46%—College Website Management System Project College Website Management System29/3/202217/6/2026
A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue is the file /cwms/classes/Master.php?f=save_contact of the component Contact Handler. The manipulation leads to persistent cross site scripting. The attack may be launched remotely and requires…
ModificadaCrítica (9.8)1.6%—Oretnom23 Simple Subscription Website21/3/202217/6/2026
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
ModificadaCrítica (9.8)1.3%—Simple Mobile Comparison Website Project Simple Mobile Comparison Website2/3/202217/6/2026
Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
ModificadaAlta (8.1)4.2%💥 PoCSimple College Website Project Simple College Website21/1/202217/6/2026
Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.
ModificadaCrítica (9.8)1.5%—Video Sharing Website Project Video Sharing Website21/12/202117/6/2026
The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the…
ModificadaMedia (6.1)25%💥 ExploitElementor Website Builder23/11/202117/6/2026
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
ModificadaMedia (6.1)1.4%💥 PoCOretnom23 Simple Subscription Website3/11/202117/6/2026
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.
ModificadaCrítica (9.8)4.7%💥 ExploitOretnom23 Simple Subscription Website3/11/202117/6/2026
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
ModificadaCrítica (9.8)1.5%—S-cms CMS Enterprise Website Construction System27/9/202117/6/2026
There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified background path without logging in to the background to obtain the background administrator authority.
ModificadaMedia (6.1)0.94%—Custom Website Data Project Custom Website Data10/9/202117/6/2026
The Custom Website Data WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter found in the ~/views/edit.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.2.
ModificadaAlta (8.8)1.6%—Jiangqie Official Website Mini Program6/9/202117/6/2026
The JiangQie Official Website Mini Program WordPress plugin before 1.1.1 does not escape or validate the id GET parameter before using it in SQL statements, leading to SQL injection issues
ModificadaCrítica (9.8)2.9%—Simple Food Website Project Simple Food Website30/7/202117/6/2026
A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.
ModificadaMedia (5.4)0.66%—E-commerce Website Project E-commerce Website23/7/202117/6/2026
Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject arbitrary web script or HTM via the subject field to feedback_process.php.
ModificadaCrítica (9.8)1.9%—E-commerce Website Project E-commerce Website23/7/202117/6/2026
Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prodViewUpdate.php.
ModificadaCrítica (9.8)1.5%—E-commerce Website Project E-commerce Website22/7/202117/6/2026
SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL statements, via the update parameter to empViewUpdate.php .
ModificadaCrítica (9.8)2.7%—Simple College Website Project Simple College Website22/7/202117/6/2026
SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php.
ModificadaMedia (5.4)0.75%—Elementor Website Builder5/4/202117/6/2026
In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’…
ModificadaMedia (5.4)0.75%—Elementor Website Builder5/4/202117/6/2026
In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’…