Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

49 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.40%—Code-projects Simple Crud Functionality5/12/202417/6/2026
A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument newtitle/newdescr leads to cross site scripting. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (5.3)0.39%—Code-projects Crud Operation System27/11/202417/6/2026
A vulnerability, which was classified as problematic, has been found in code-projects Crud Operation System 1.0. This issue affects some unknown processing of the file /add.php. The manipulation of the argument saddress leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed…
AnalizadaMedia (6.9)0.70%—Code-projects Crud Operation System10/10/202417/6/2026
A vulnerability classified as critical was found in code-projects Crud Operation System 1.0. This vulnerability affects unknown code of the file delete.php. The manipulation of the argument sid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.3)0.61%—Code-projects Crud Operation System20/9/202417/6/2026
A vulnerability, which was classified as critical, was found in code-projects Crud Operation System 1.0. Affected is an unknown function of the file updata.php. The manipulation of the argument sid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (6.9)0.94%—Code-projects Crud Operation System15/9/202417/6/2026
A vulnerability was found in code-projects Crud Operation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file savedata.php. The manipulation of the argument sname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (5.3)0.68%—Code-projects Crud Operation System13/9/202417/6/2026
A vulnerability was found in code-projects Crud Operation System 1.0. It has been classified as critical. This affects an unknown part of the file /updatedata.php. The manipulation of the argument sid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (5.3)0.41%—Rems PHP Crud7/9/202417/6/2026
A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update.php. The manipulation of the argument tbl_person_id/first_name/middle_name/last_name leads to sql injection. The attack can be initiated remotely. The exploit…
AnalizadaMedia (5.3)0.40%—Rems PHP Crud7/9/202417/6/2026
A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit…
AnalizadaMedia (5.3)0.31%—Rems PHP Crud7/9/202417/6/2026
A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/Add.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. The attack may be launched remotely. The exploit…
AnalizadaMedia (5.3)0.44%—Rems PHP Crud7/9/202417/6/2026
A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete.php of the component Delete Person Handler. The manipulation of the argument person leads to sql injection. The attack can be launched…
ModificadaAlta (7.8)1.1%—J11g Cruddiy24/6/202417/6/2026
The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server. The exploitation risk is limited since CRUDDIY is meant to be launched locally. Nevertheless, a user with the project running on their computer might visit a website which would send such a…
AnalizadaCrítica (9.8)0.69%—Remyandrade Crud Without Page Reload/refresh12/3/202417/6/2026
A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file add_user.php. The manipulation of the argument city leads to sql injection. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (6.1)0.57%—Remyandrade Crud Without Page Reload/refresh3/2/202417/6/2026
A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file fetch_data.php. The manipulation of the argument username/city leads to cross site scripting. The attack may be launched remotely. The exploit has…
ModificadaCrítica (9.8)0.78%—Code-projects Simple Crud Functionality17/11/202317/6/2026
SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands via the 'title' parameter.
ModificadaMedia (6.1)0.23%—Crudlab Jazz Popups7/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab Jazz Popups leads to Stored XSS.This issue affects Jazz Popups: from n/a through 1.8.7.
ModificadaAlta (8.8)0.25%—Crudlab WP Like Button3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab WP Like Button plugin <= 1.7.0 versions.
ModificadaMedia (6.1)0.38%—Crudlab Jazz Popups18/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions.
ModificadaAlta (8.8)1.5%—AEB Cruddl8/9/202217/6/2026
cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prior to versions 2.7.0 and 3.0.2 is used to generate a schema that uses `@flexSearchFulltext`, users of that schema may be able to inject arbitrary AQL queries that will be…
ModificadaCrítica (9.6)2.2%—PHP Crud Without Refresh/reload Using Ajax AND Datatables Tutorial Project PHP Crud Without Refresh/reload Using Ajax AND Datatables Tutorial24/1/202217/6/2026
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.
ModificadaMedia (5.4)0.60%—Egavilanmedia Phpcrud28/1/202117/6/2026
Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'.
ModificadaMedia (6.1)1.3%—Backpackforlaravel Backpack\crud8/8/201917/6/2026
The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.
ModificadaMedia (5.3)45%💥 ExploitCrudlab WP Like Button5/7/201917/6/2026
An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to…
ModificadaMedia (6.1)1.1%—Crud-file-server Project Crud-file-server7/6/201817/6/2026
crud-file-server node module before 0.8.0 suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
ModificadaAlta (7.5)2.2%—Crud-file-server Project Crud-file-server29/5/201817/6/2026
crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url, which allows a malicious user to read content of any file with known path.
Orbitaley — Vulnerabilidades