Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2087 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.49% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 15/9/2025 | 17/6/2026 | A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The impacted element is an unknown function of the file /admin/controller/student_controller.php. Such manipulation of the argument new_image leads to unrestricted upload. The attack may be performed from… | |
| Analizada | Media (5.5) | 0.46% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 15/9/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The affected element is an unknown function of the file /admin/controller/faculty_controller.php. This manipulation of the argument new_image causes unrestricted upload. The attack is possible to be… | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fullname', 'location' and 'message' parameters via POST at the endpoint '/ofrs/reporting.php'. This vulnerability could allow a remote user… | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'remark', 'status' and 'takeaction' parameters via POST at the endpoint '/ofrs/admin/request-details.php'. This vulnerability could allow a… | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fromdate' and 'todate' parameters via POST at the endpoint '/ofrs/admin/bwdates-report-result.php'. This vulnerability could allow a remote… | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'requestid' parameter in the endpoint '/ofrs/details.php'. | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'. | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'remark', 'status' and 'requestid' parameters in the endpoint '/ofrs/admin/request-details.php'. | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'. | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 30/9/2026 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname' parameters via POST at the endpoint… | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 30/9/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'. | |
| Analizada | Alta (7.8) | 0.71% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server | 9/9/2025 | 17/6/2026 | Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.1) | 0.63% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+2 | 9/9/2025 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (8.8) | 20% | 💥 PoC | Microsoft Sharepoint Server | 9/9/2025 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Media (5.5) | 0.42% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 26/8/2025 | 17/6/2026 | A vulnerability has been found in 1000projects Online Project Report Submission and Evaluation System 1.0. This issue affects some unknown processing of the file /admin/controller/delete_group_student.php. The manipulation of the argument batch_id leads to sql injection. The attack can be initiated remotely. The… | |
| Analizada | Baja (2.1) | 0.35% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 26/8/2025 | 17/6/2026 | A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this issue is some unknown functionality of the file /admin/add_title.php. Such manipulation of the argument Title leads to cross site scripting. The attack may be performed from a remote… | |
| Analizada | Baja (2.1) | 0.35% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 26/8/2025 | 17/6/2026 | A weakness has been identified in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this vulnerability is an unknown functionality of the file /rse/admin/edit_faculty.php?id=2. This manipulation of the argument Name causes cross site scripting. The attack is possible to be carried… | |
| Analizada | Baja (2.1) | 0.35% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 26/8/2025 | 17/6/2026 | A security flaw has been discovered in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected is an unknown function of the file /admin/add_student.php. The manipulation of the argument address results in cross site scripting. The attack can be executed remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.36% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 26/8/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Online Project Report Submission and Evaluation System 1.0. This affects an unknown function of the file /admin/edit_title.php?id=1. Executing manipulation of the argument desc can lead to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Crítica (9.8) | 0.80% | — | Anji-plus Aj-reportAI | 22/8/2025 | 17/6/2026 | An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted URL. | |
| Analizada | Media (5.3) | 0.49% | — | Jeecg Jimureport | 14/8/2025 | 17/6/2026 | A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. The vendor response to… | |
| Aplazada | Crítica (10) | 2.7% | 💥 Exploit | Snort ReportAINmapAINbtscanAI | 13/8/2025 | 16/6/2026 | Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to properly sanitize user input passed via the target GET parameter, allowing attackers to inject arbitrary shell commands. Exploitation requires no authentication and can result… | |
| Analizada | Media (6.9) | 0.50% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+22 | 13/8/2025 | 17/6/2026 | An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.34% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/8/2025 | 17/6/2026 | When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are… | |
| Analizada | Alta (7.1) | 16% | — | Microsoft Sharepoint Server | 12/8/2025 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |