Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3004 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.24% | — | Collabora OnlineAILibreofficeAI | 6/2/2026 | 17/6/2026 | Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Development Edition version 25.04.08.2 and prior to Collabora Online versions 23.05.20.1, 24.04.17.3, and 25.04.7.5, a user with view-only rights and no download privileges can obtain a local copy of a… | |
| Aplazada | Alta (7.5) | 0.45% | — | Lupsonline SEO FlowAI | 4/2/2026 | 17/6/2026 | The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the checkBlogAuthentication() and checkCategoryAuthentication() functions in all versions up to, and including, 2.2.1. These authorization functions only implement basic API key… | |
| Aplazada | Media (5.1) | 0.33% | — | Online Inventory ManagerAI | 3/2/2026 | 17/6/2026 | Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side… | |
| Analizada | Alta (8.8) | 0.56% | — | Sunnygkp10 Online-exam-system- | 30/1/2026 | 17/6/2026 | Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through the 'fid' parameter. Attackers can inject malicious SQL code into the 'fid' parameter to potentially extract, modify, or delete database information. | |
| Analizada | Alta (8.8) | 0.41% | — | Sunnygkp10 Online-exam-system- | 30/1/2026 | 17/6/2026 | Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters. | |
| Aplazada | Media (5.1) | 0.20% | — | Sistem Informasi Pengumuman Kelulusan OnlineAI | 30/1/2026 | 17/6/2026 | Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized admin users through the tambahuser.php endpoint. Attackers can craft a malicious HTML form to submit admin credentials and create new administrative accounts without the… | |
| Aplazada | Alta (8.6) | 0.34% | 💥 PoC | Kodmatic Computer Software Online Exam AND AssessmentAI | 30/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer Software Tourism Construction Industry and Trade Ltd. Co. Online Exam and Assessment allows SQL Injection. This issue affects Online Exam and Assessment: through 30012026. NOTE: The vendor was… | |
| Analizada | Media (5.5) | 0.47% | — | Fabian Online Music Site | 28/1/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Administrator/PHP/AdminReply.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Media (5.5) | 0.47% | — | Fabian Online Music Site | 28/1/2026 | 17/6/2026 | A weakness has been identified in code-projects Online Music Site 1.0. This affects an unknown function of the file /Administrator/PHP/AdminEditUser.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Baja (2) | 0.41% | — | Fabian Online Music Site | 28/1/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminAddCategory.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used… | |
| Aplazada | Alta (8.8) | 0.28% | — | Testa Online Test Management SystemAI | 27/1/2026 | 17/6/2026 | Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'q' search parameter. Attackers can inject malicious SQL code in the search field to extract database information, potentially accessing sensitive user or system data. | |
| Analizada | Media (5.5) | 0.56% | — | Fabian Online Music Site | 26/1/2026 | 17/6/2026 | A flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminDeleteUser.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.42% | — | Fabian Online Examination System | 26/1/2026 | 17/6/2026 | A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /admin_pic.php. Executing a manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.53% | — | Fabian Online Examination System | 26/1/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login Page. Performing a manipulation of the argument User results in sql injection. The attack is possible to be carried out remotely. The… | |
| Analizada | Baja (2) | 0.30% | — | Fabian Online Examination System | 26/1/2026 | 17/6/2026 | A vulnerability has been found in code-projects Online Examination System 1.0. Affected is an unknown function of the component Add Pages. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.5) | 0.17% | 💥 PoC | Phpgurukul Online Course Registration | 22/1/2026 | 17/6/2026 | PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf of authenticated administrators by tricking them into visiting a malicious webpage. | |
| Aplazada | Crítica (9.8) | 0.45% | — | Themerex Sound Musical Instruments Online StoreAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue affects Sound | Musical Instruments Online Store: from n/a through <= 1.6.9. | |
| Analizada | Media (5.5) | 6.9% | — | Tosei-corporation Online Store Management System | 19/1/2026 | 17/6/2026 | A vulnerability was determined in Tosei Online Store Management System ネット店舗管理システム 1.01. The affected element is an unknown function of the file /cgi-bin/imode_alldata.php. Executing a manipulation of the argument DevId can lead to command injection. The attack can be executed remotely. The exploit has been publicly… | |
| Analizada | Media (5.5) | 0.39% | — | Adonesevangelista Online Frozen Foods Ordering System | 19/1/2026 | 17/6/2026 | A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This issue affects some unknown processing of the file /order_online.php. Executing a manipulation of the argument product_name can lead to sql injection. The attack can be launched remotely. The exploit has been made available to… | |
| Analizada | Alta (7.8) | 0.50% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 13/1/2026 | 17/6/2026 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.61% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server | 13/1/2026 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.50% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 13/1/2026 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Crítica (9.1) | 0.40% | — | Jayesh Online Exam System | 12/1/2026 | 17/6/2026 | A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request. | |
| Analizada | Media (5.5) | 0.37% | — | Fabian Online Music Site | 12/1/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminUpdateUser.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.38% | — | Fabian Online Music Site | 12/1/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. The manipulation of the argument txtusername leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and… |