Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.45%—Munyweki Insurance Management System24/7/202417/6/2026
A vulnerability classified as problematic has been found in SourceCodester Insurance Management System 1.0. This affects an unknown part of the file /Script/admin/core/update_sub_category. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit…
ModificadaMedia (6.1)0.30%—Aegon Life Insurance Management System14/6/202417/6/2026
A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php.
ModificadaAlta (8.8)2.3%—Projectworlds Life Insurance Management System14/6/202417/6/2026
Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.
AplazadaAlta (8.1)0.59%—Insurance Management SystemAI26/4/202417/6/2026
An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /admin/core/new_staff.
AnalizadaMedia (6.1)0.47%—Munyweki Insurance Management System15/4/202417/6/2026
Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at /core/new_category2.
AnalizadaMedia (6.1)0.83%—Munyweki Insurance Management System28/3/202417/6/2026
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the City input field.
ModificadaMedia (6.1)0.66%—Munyweki Insurance Management System28/3/20249/7/2026
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.
AnalizadaMedia (6.4)0.90%—Munyweki Insurance Management System28/3/202417/6/2026
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Email input field.
AnalizadaMedia (6.3)0.82%—Munyweki Insurance Management System28/3/202417/6/2026
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Street input field.
AnalizadaMedia (6.1)0.85%—Munyweki Insurance Management System28/3/202417/6/2026
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Last Name input field.
AnalizadaMedia (6.1)0.31%—Munyweki Insurance Management System11/3/202417/6/2026
Cross Site Scripting (XSS) vulnerability in Sourcecodester Insurance Management System 1.0 allows attackers to run arbitrary code via the Subject and Description fields when submitting a support ticket.
AnalizadaMedia (5.3)0.61%—Munyweki Insurance Management System3/3/202417/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Insurance Management System 1.0. This issue affects some unknown processing. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the public and may be…
ModificadaMedia (6.1)0.36%—Phpscriptpoint Insurance24/7/202317/6/2026
A vulnerability was found in phpscriptpoint Insurance 1.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /search.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The identifier VDB-235213 was assigned to this…
ModificadaMedia (6.1)0.36%—Phpscriptpoint Insurance24/7/202317/6/2026
A vulnerability was found in phpscriptpoint Insurance 1.2. It has been classified as problematic. Affected is an unknown function of the file /page.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-235212. NOTE: The vendor was…
ModificadaCrítica (9.8)0.80%—Janobe Life Insurance Management System16/7/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Life Insurance Management System 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public…
ModificadaMedia (6.1)0.59%—Janobe Life Insurance Management System8/6/202317/6/2026
A vulnerability was found in SourceCodester Life Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file insertNominee.php of the component POST Parameter Handler. The manipulation of the argument nominee_id leads to cross site…
ModificadaMedia (6.5)0.31%—Hasthemes WP Insurance27/3/202317/6/2026
The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaMedia (5.5)0.19%—NHI Health Insurance WEB Service Component2/8/202217/6/2026
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.
ModificadaMedia (5.5)0.19%—NHI Health Insurance WEB Service Component2/8/202217/6/2026
The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.
ModificadaAlta (7.8)0.23%—NHI Health Insurance WEB Service Component2/8/202217/6/2026
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A local area network attacker with general user privilege can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service.
ModificadaAlta (7.5)1.5%—NHI Health Insurance WEB Service Component20/6/202217/6/2026
NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate service without authentication, which…
AnalizadaAlta (7.2)1.0%—Angeljudesuarez Insurance Management System12/5/202217/6/2026
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editNominee.php?nominee_id=.
AnalizadaCrítica (9.8)1.1%—Angeljudesuarez Insurance Management System12/5/202217/6/2026
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=.
AnalizadaCrítica (9.8)1.1%—Angeljudesuarez Insurance Management System12/5/202217/6/2026
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=.
AnalizadaCrítica (9.8)1.1%—Angeljudesuarez Insurance Management System12/5/202217/6/2026
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editClient.php?client_id=.
Orbitaley — Vulnerabilidades