Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.60% | — | Go-admin Go-cms | 24/1/2025 | 17/6/2026 | SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload. | |
| Aplazada | Media (4.3) | 0.38% | — | Bowo Admin Site EnhancementsAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 7.6.2. | |
| Aplazada | Media (6.4) | 0.42% | — | PhpmyadminAI | 23/1/2025 | 17/6/2026 | An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database name could be used for XSS. | |
| Aplazada | Media (6.4) | 0.41% | — | PhpmyadminAI | 23/1/2025 | 17/6/2026 | An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab. | |
| Aplazada | Alta (7.1) | 0.39% | — | Phpdevca Admin Menu OrganizerAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpdevca Admin Menu Organizer admin-menu-organizer allows Reflected XSS.This issue affects Admin Menu Organizer: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.20% | — | Matt Gibbs Admin CleanupAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Matt Gibbs Admin Cleanup admin-cleanup allows Stored XSS.This issue affects Admin Cleanup: from n/a through <= 1.0.2. | |
| Aplazada | Alta (7.1) | 0.20% | — | Fuzzguard Style AdminAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FuzzGuard Style Admin style-admin allows Stored XSS.This issue affects Style Admin: from n/a through <= 1.4.3. | |
| Aplazada | Media (5.3) | 0.41% | — | Reckcn SppanadadminAI | 12/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in reckcn SPPanAdmin 1.0. Affected is an unknown function of the file /;/admin/role/edit. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Alta (7.1) | 0.15% | — | Dylan James Zephyr Modern Admin ThemeAI | 9/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Admin Theme zephyr-modern-admin-theme allows Cross Site Request Forgery.This issue affects Zephyr Admin Theme: from n/a through <= 1.4.1. | |
| Analizada | Alta (7.5) | 0.45% | — | Pgadmin | 9/1/2025 | 17/6/2026 | A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if multiple connection attempts occur simultaneously. | |
| Modificada | Alta (7.1) | 0.17% | — | Pgadmin Pgagent | 7/1/2025 | 17/6/2026 | When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local attacker to pre-create the directory and… | |
| Aplazada | Media (4.3) | 0.20% | — | Digitalzoomstudio Admin Debug Wordpress Enable DebugAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in digitalzoomstudio Admin debug wordpress – enable debug dzs-enable-debug allows Cross Site Request Forgery.This issue affects Admin debug wordpress – enable debug: from n/a through <= 1.0.13. | |
| Aplazada | Media (4.3) | 0.33% | — | Martin Gibson WP Custom Admin InterfaceAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP Custom Admin Interface allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Custom Admin Interface: from n/a through 7.32. | |
| Analizada | Media (4.8) | 0.27% | — | Dcatadmin Dcat Admin | 27/12/2024 | 17/6/2026 | Dcat-Admin v2.2.0-beta and v2.2.2-beta contains a Cross-Site Scripting (XSS) vulnerability via /admin/auth/menu and /admin/auth/extensions. | |
| Analizada | Media (4.8) | 0.33% | — | Dcatadmin Dcat Admin | 27/12/2024 | 17/6/2026 | Dcat Admin v2.2.0-beta contains a cross-site scripting (XSS) vulnerability in /admin/articles/create. | |
| Analizada | Media (5.3) | 0.54% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability has been found in code-projects Simple Admin Panel 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file updateOrderStatus.php. The manipulation of the argument record leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0. Affected is an unknown function of the file addVariationController.php. The manipulation of the argument qty leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.59% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Simple Admin Panel 1.0. This issue affects some unknown processing of the file catDeleteController.php. The manipulation of the argument record leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.59% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Simple Admin Panel 1.0. This vulnerability affects unknown code of the file editItemForm.php. The manipulation of the argument record leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.41% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Simple Admin Panel 1.0. This affects an unknown part of the file updateItemController.php. The manipulation of the argument p_desk leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.41% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file updateItemController.php. The manipulation of the argument p_name/p_desc leads to cross site scripting. The attack may be launched remotely. | |
| Analizada | Media (5.3) | 0.41% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file addSizeController.php. The manipulation of the argument size leads to cross site scripting. The attack can be launched remotely. | |
| Analizada | Media (5.3) | 0.57% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been classified as critical. Affected is an unknown function of the file /addCatController.php. The manipulation of the argument size leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.41% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Simple Admin Panel 1.0 and classified as problematic. This issue affects some unknown processing of the file addCatController.php. The manipulation of the argument c_name leads to cross site scripting. The attack may be initiated remotely. | |
| Analizada | Media (5.3) | 0.41% | — | Code-projects Simple Admin Panel | 26/12/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0. This affects an unknown part. The manipulation of the argument c_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |