Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.30% | — | Aegon Life Insurance Management System | 14/6/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php. | |
| Modificada | Alta (8.8) | 2.3% | — | Projectworlds Life Insurance Management System | 14/6/2024 | 17/6/2026 | Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php. | |
| Aplazada | Alta (8.1) | 0.59% | — | Insurance Management SystemAI | 26/4/2024 | 17/6/2026 | An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /admin/core/new_staff. | |
| Analizada | Media (6.1) | 0.47% | — | Munyweki Insurance Management System | 15/4/2024 | 17/6/2026 | Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at /core/new_category2. | |
| Analizada | Media (6.1) | 0.83% | — | Munyweki Insurance Management System | 28/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the City input field. | |
| Modificada | Media (6.1) | 0.66% | — | Munyweki Insurance Management System | 28/3/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field. | |
| Analizada | Media (6.4) | 0.90% | — | Munyweki Insurance Management System | 28/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Email input field. | |
| Analizada | Media (6.3) | 0.82% | — | Munyweki Insurance Management System | 28/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Street input field. | |
| Analizada | Media (6.1) | 0.85% | — | Munyweki Insurance Management System | 28/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Last Name input field. | |
| Analizada | Media (6.1) | 0.31% | — | Munyweki Insurance Management System | 11/3/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Sourcecodester Insurance Management System 1.0 allows attackers to run arbitrary code via the Subject and Description fields when submitting a support ticket. | |
| Analizada | Media (5.3) | 0.61% | — | Munyweki Insurance Management System | 3/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Insurance Management System 1.0. This issue affects some unknown processing. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 0.80% | — | Janobe Life Insurance Management System | 16/7/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Life Insurance Management System 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (6.1) | 0.59% | — | Janobe Life Insurance Management System | 8/6/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Life Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file insertNominee.php of the component POST Parameter Handler. The manipulation of the argument nominee_id leads to cross site… | |
| Analizada | Alta (7.2) | 1.0% | — | Angeljudesuarez Insurance Management System | 12/5/2022 | 17/6/2026 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editNominee.php?nominee_id=. | |
| Analizada | Crítica (9.8) | 1.1% | — | Angeljudesuarez Insurance Management System | 12/5/2022 | 17/6/2026 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=. | |
| Analizada | Crítica (9.8) | 1.1% | — | Angeljudesuarez Insurance Management System | 12/5/2022 | 17/6/2026 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=. | |
| Analizada | Crítica (9.8) | 1.1% | — | Angeljudesuarez Insurance Management System | 12/5/2022 | 17/6/2026 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editClient.php?client_id=. | |
| Analizada | Crítica (9.8) | 1.1% | — | Angeljudesuarez Insurance Management System | 12/5/2022 | 17/6/2026 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/clientStatus.php?client_id=. | |
| Analizada | Crítica (9.8) | 1.1% | — | Angeljudesuarez Insurance Management System | 5/4/2022 | 17/6/2026 | Insurance Management System 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. |