Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.71% | — | Garage Management System Project Garage Management System | 29/7/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This issue affects some unknown processing of the file /php_action/createUser.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed… | |
| Modificada | Alta (8.8) | 0.69% | — | Garage Management System Project Garage Management System | 29/7/2022 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Garage Management System 1.0. This vulnerability affects unknown code of the file /edituser.php. The manipulation of the argument id with the input -2'%20UNION%20select%2011,user(),333,444--+ leads to sql injection. The attack can be initiated… | |
| Modificada | Crítica (9.8) | 1.3% | — | Garage Management System Project Garage Management System | 26/7/2022 | 17/6/2026 | Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | |
| Modificada | Alta (8.8) | 0.90% | — | Garage Management System Project Garage Management System | 19/7/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Garage Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /editbrand.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 4.9% | 💥 Exploit | Garage Management System Project Garage Management System | 19/7/2022 | 17/6/2026 | A vulnerability has been found in SourceCodester Garage Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username with the input 1@a.com' AND (SELECT 6427 FROM (SELECT(SLEEP(5)))LwLu) AND 'hsvT'='hsvT leads to sql… | |
| Modificada | Alta (7.8) | 1.1% | — | Apple GaragebandApple Logic PRO XApple Macos | 18/3/2022 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution. | |
| Modificada | Alta (7.8) | 1.1% | — | Apple GaragebandApple Logic PRO XApple Macos | 18/3/2022 | 17/6/2026 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution. | |
| Modificada | Media (5.5) | 0.25% | — | Apple Garageband | 8/9/2021 | 17/6/2026 | This issue was addressed by removing additional entitlements. This issue is fixed in GarageBand 10.4.3. A local attacker may be able to read sensitive information. | |
| Modificada | Alta (7.8) | 1.5% | — | Apple Garageband | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. GarageBand before 10.1.6 is affected. The issue involves the "Projects" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted GarageBand project file. | |
| Modificada | Alta (8.8) | 2.0% | — | Apple Logic PRO XApple Garageband | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. GarageBand before 10.1.5 is affected. Logic Pro X before 10.3 is affected. The issue involves the "Projects" component, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GarageBand project file. | |
| Modificada | Media (4.3) | 1.6% | — | Garagesale Project Garagesale | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in templates/printAdminUsersList_Footer.tpl.php in the GarageSale plugin before 1.2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Media (5) | 16% | 💥 Exploit | Code-garage COM Noticeboard | 3/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Garagesalesjunkie Garagesales Script | 14/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Garagesalesjunkie Garagesales Script | 14/8/2009 | 16/6/2026 | SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL commands via the key parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Apple Garageband | 4/8/2009 | 16/6/2026 | Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, which makes it easier for remote web servers to track users. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Phpbb Garage | 4/12/2007 | 16/6/2026 | SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id parameter in a search action in browse mode. |