Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.46% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 15/9/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The affected element is an unknown function of the file /admin/controller/faculty_controller.php. This manipulation of the argument new_image causes unrestricted upload. The attack is possible to be… | |
| Analizada | Media (5.5) | 0.42% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 26/8/2025 | 17/6/2026 | A vulnerability has been found in 1000projects Online Project Report Submission and Evaluation System 1.0. This issue affects some unknown processing of the file /admin/controller/delete_group_student.php. The manipulation of the argument batch_id leads to sql injection. The attack can be initiated remotely. The… | |
| Analizada | Baja (2.1) | 0.35% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 26/8/2025 | 17/6/2026 | A security vulnerability has been detected in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this issue is some unknown functionality of the file /admin/add_title.php. Such manipulation of the argument Title leads to cross site scripting. The attack may be performed from a remote… | |
| Analizada | Baja (2.1) | 0.35% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 26/8/2025 | 17/6/2026 | A weakness has been identified in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected by this vulnerability is an unknown functionality of the file /rse/admin/edit_faculty.php?id=2. This manipulation of the argument Name causes cross site scripting. The attack is possible to be carried… | |
| Analizada | Baja (2.1) | 0.35% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 26/8/2025 | 17/6/2026 | A security flaw has been discovered in 1000projects Online Project Report Submission and Evaluation System 1.0. Affected is an unknown function of the file /admin/add_student.php. The manipulation of the argument address results in cross site scripting. The attack can be executed remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.36% | — | 1000projects Online Student Project Report Submission AND Evaluation System | 26/8/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Online Project Report Submission and Evaluation System 1.0. This affects an unknown function of the file /admin/edit_title.php?id=1. Executing manipulation of the argument desc can lead to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (6.4) | 0.25% | — | Valuation CalculatorAI | 23/7/2025 | 17/6/2026 | The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Crítica (9.1) | 0.62% | — | Luajit | 7/7/2025 | 17/6/2026 | LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c. | |
| Modificada | Alta (7.5) | 0.53% | — | Luajit | 7/7/2025 | 17/6/2026 | LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS). | |
| Modificada | Crítica (9.8) | 0.56% | — | Luajit | 7/7/2025 | 17/6/2026 | LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c. | |
| Aplazada | Baja (2.1) | 0.32% | — | Conjure Position Department Service Quality Evaluation SystemAI | 29/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Conjure Position Department Service Quality Evaluation System up to 1.0.11. Affected by this issue is the function eval of the file public/assets/less/bootstrap-less/mixins/head.php. The manipulation of the argument payload leads to backdoor. The… | |
| Modificada | Alta (7.7) | 0.81% | — | Openresty Lua-nginx-module | 22/4/2025 | 17/6/2026 | An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request. | |
| Aplazada | Alta (8.2) | 0.52% | — | Lua-shmemAI | 27/6/2024 | 17/6/2026 | lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function. | |
| Aplazada | Alta (7.5) | 0.42% | — | Waxlab WAXAILUAAI | 20/5/2024 | 17/6/2026 | Buffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the Lua library component. | |
| Aplazada | Alta (8.1) | 0.53% | — | Cdbattags Lua-resty-jwtAI | 24/4/2024 | 17/6/2026 | cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by crafting a JWT with an enc header with the value A256GCM. | |
| Aplazada | Media (4.7) | 0.55% | — | Sanluan Flipped-auroraAISanluan Gin-vue-adminAI | 16/4/2024 | 17/6/2026 | An issue in sanluan flipped-aurora gin-vue-admin 2.4.x allows an attacker to escalate privileges via the Session Expiration component. | |
| Modificada | Alta (7.5) | 1.1% | — | Daurnimator Lua-http | 5/9/2023 | 17/6/2026 | Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop. This issue affects lua-http: all… | |
| Analizada | Media (5.4) | 0.74% | — | Faculty Evaluation System Project Faculty Evaluation System | 1/8/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the page parameter. | |
| Modificada | Media (5.4) | 0.50% | — | Jenkins Benchmark Evaluator | 12/7/2023 | 17/6/2026 | A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and to check for the existence of directories, `.csv`, and `.ycsb` files on the Jenkins controller file system. | |
| Modificada | Alta (8.8) | 0.49% | — | Jenkins Benchmark Evaluator | 12/7/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers to connect to an attacker-specified URL and to check for the existence of directories, `.csv`, and `.ycsb` files on the Jenkins controller file system. | |
| Modificada | Alta (7.5) | 0.71% | — | Cloudflare Lua-resty-json | 14/6/2023 | 17/6/2026 | A debug function in the lua-resty-json package, up to commit id 3ef9492bd3a44d9e51301d6adc3cd1789c8f534a (merged in PR #14) contained an out of bounds access bug that could have allowed an attacker to launch a DoS if the function was used to parse untrusted input data. It is important to note that because this debug… | |
| Modificada | Alta (7.2) | 1.1% | — | Faculty Evaluation System Project Faculty Evaluation System | 6/6/2023 | 17/6/2026 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user. | |
| Modificada | Crítica (9.8) | 0.71% | — | Faculty Evaluation System Project Faculty Evaluation System | 29/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affected by this issue is some unknown functionality of the file index.php?page=edit_user. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Modificada | Alta (7.2) | 15% | — | Faculty Evaluation System Project Faculty Evaluation System | 26/5/2023 | 17/6/2026 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user. | |
| Modificada | Alta (7.2) | 3.3% | — | Faculty Evaluation System Project Faculty Evaluation System | 26/5/2023 | 17/6/2026 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=. |