Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.36% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.36% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assessments/pretest/btn_functions.php. Such manipulation of the argument difficulty_id leads to sql injection. The attack can be executed remotely. The exploit is publicly… | |
| Analizada | Media (5.5) | 0.34% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit… | |
| Analizada | Media (5.5) | 0.40% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (5.5) | 0.34% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was determined in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/admins/assessments/pretest/exam-delete.php. This manipulation of the argument test_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Reviewer System 1.0. This issue affects some unknown processing of the file /system/system/admins/assessments/pretest/exam-update.php. The manipulation of the argument test_id results in sql injection. The attack may be performed from remote. The exploit has been made… | |
| Analizada | Media (5.5) | 0.38% | — | Fabian Online Reviewer System | 9/2/2026 | 17/6/2026 | A vulnerability has been found in code-projects Online Reviewer System 1.0. This vulnerability affects unknown code of the file /system/system/admins/assessments/pretest/questions-view.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.47% | — | Fabian Online Reviewer System | 8/2/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /login/index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Alta (7.1) | 0.38% | — | ED Atrero Album ReviewerAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ed atrero Album Reviewer albumreviewer allows Stored XSS.This issue affects Album Reviewer: from n/a through <= 2.0.2. | |
| Aplazada | Alta (7.1) | 0.26% | — | Trustist ReviewerAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trustist TRUSTist REVIEWer trustist-reviewer allows Reflected XSS.This issue affects TRUSTist REVIEWer: from n/a through <= 2.0. | |
| Analizada | Crítica (9.8) | 0.83% | — | Janobe Online Reviewer System | 9/5/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Reviewer System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /reviewer/system/system/admins/manage/users/user-update.php of the component GET Parameter Handler. The manipulation of the argument user_id leads to sql… | |
| Modificada | Alta (7.2) | 0.73% | — | Online Reviewer Management System Project Online Reviewer Management System | 28/2/2023 | 17/6/2026 | An issue was discovered in Online Reviewer Management System v1.0. There is a SQL injection that can directly issue instructions to the background database system via reviewer_0/admins/assessments/course/course-update.php. | |
| Modificada | Media (4.8) | 0.46% | — | Online Reviewer Management System Project Online Reviewer Management System | 28/2/2023 | 17/6/2026 | An issue was discovered in Online Reviewer Management System v1.0. There is a XSS vulnerability via reviewer_0/admins/assessments/course/course-update.php. | |
| Modificada | Crítica (9.8) | 0.81% | — | Online Reviewer Management System Project Online Reviewer Management System | 26/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Reviewer Management System 1.0. Affected is an unknown function of the file /reviewer_0/admins/assessments/pretest/questions-view.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely.… | |
| Modificada | Alta (7.2) | 1.0% | — | Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System | 20/10/2022 | 17/6/2026 | Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload. | |
| Modificada | Media (5.4) | 0.50% | — | Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System | 20/10/2022 | 17/6/2026 | Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List. | |
| Modificada | Alta (8.8) | 0.51% | — | Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System | 20/10/2022 | 17/6/2026 | Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List. | |
| Modificada | Alta (8.8) | 1.0% | — | Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System | 20/10/2022 | 17/6/2026 | In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload. | |
| Modificada | Media (6.5) | 0.62% | — | Simple Exam Reviewer Management System Project Simple Exam Reviewer Management System | 20/10/2022 | 17/6/2026 | In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges. | |
| Modificada | Alta (8.8) | 23% | — | Exam Reviewer Management System Project Exam Reviewer Management System | 27/9/2022 | 17/6/2026 | In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE). | |
| Modificada | Crítica (9.8) | 1.3% | — | Exam Reviewer Management System Project Exam Reviewer Management System | 27/9/2022 | 17/6/2026 | Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter. | |
| Modificada | Crítica (9.8) | 1.1% | — | Sourcecodester Online Reviewer System Project Sourcecodester Online Reviewer System | 20/1/2022 | 17/6/2026 | An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter. | |
| Analizada | Crítica (9.8) | 7.2% | 💥 PoC | Janobe Online Reviewer System | 29/10/2021 | 17/6/2026 | Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters.. | |
| Analizada | Crítica (9.8) | 2.2% | — | Janobe Online Reviewer System | 14/4/2021 | 17/6/2026 | Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload. | |
| Modificada | Alta (7.5) | 2.0% | — | Prismjs Previewers | 7/8/2020 | 17/6/2026 | Prism is vulnerable to Cross-Site Scripting. The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to execute arbitrary code in Safari and Internet Explorer. This impacts all Safari and Internet Explorer users of Prism >=v1.1.0 that use the _Previewers_ plugin (>=v1.10.0) or the… |