Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Video Sharing Website Project Video Sharing Website | 21/12/2021 | 17/6/2026 | The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted with that domain, indicating that the… | |
| Modificada | Crítica (9.8) | 2.9% | — | Simple Food Website Project Simple Food Website | 30/7/2021 | 17/6/2026 | A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin. | |
| Modificada | Media (5.4) | 0.66% | — | E-commerce Website Project E-commerce Website | 23/7/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject arbitrary web script or HTM via the subject field to feedback_process.php. | |
| Modificada | Crítica (9.8) | 1.9% | — | E-commerce Website Project E-commerce Website | 23/7/2021 | 17/6/2026 | Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary code via the file upload to prodViewUpdate.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | E-commerce Website Project E-commerce Website | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL statements, via the update parameter to empViewUpdate.php . | |
| Modificada | Crítica (9.8) | 2.7% | — | Simple College Website Project Simple College Website | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary SQL statements via the id parameter to news.php. | |
| Modificada | Crítica (9.8) | 2.3% | — | Education Website Project Education Website | 19/6/2019 | 17/6/2026 | SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter. | |
| Modificada | Media (5.4) | 0.64% | — | Chartered Accountant \ Auditor Website Project | 6/6/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field. | |
| Modificada | Media (6.5) | 1.4% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory. | |
| Modificada | Media (6.5) | 1.6% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field. | |
| Modificada | Media (5.4) | 0.65% | — | Chartered Accountant \ Auditor Website Project | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field. | |
| Modificada | Alta (8.8) | 0.51% | — | Chartered Accountant \ Auditor Website Project | 10/8/2018 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | SSH Companywebsite Project SSH Companywebsite | 20/7/2018 | 17/6/2026 | An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type. | |
| Modificada | Crítica (9.8) | 1.1% | — | SSH Companywebsite Project SSH Companywebsite | 20/7/2018 | 17/6/2026 | An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter. | |
| Modificada | Media (6.1) | 1.0% | — | Chartered Accountant \ Auditor Website Project | 9/7/2018 | 17/6/2026 | PHP Scripts Mall Auditor Website 2.0.1 has XSS via the lastname or firstname parameter. | |
| Modificada | Crítica (9.8) | 3.0% | — | CMS Auditor Website Project CMS Auditor Website | 13/12/2017 | 17/6/2026 | CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail. | |
| Modificada | Alta (7.5) | 0.97% | — | Preprojects PHP Jobwebsite PRO | 27/1/2009 | 16/6/2026 | SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action. | |
| Modificada | Media (4.3) | 1.5% | — | Preprojects PHP Jobwebsite PRO | 27/1/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in siteadmin/forgot.php in PHP JOBWEBSITE PRO allow remote attackers to inject arbitrary web script or HTML via (1) the adname parameter in a Submit action or (2) the UserName field. | |
| Modificada | Alta (7.5) | 1.0% | — | Preprojects PHP Jobwebsite PRO | 30/6/2008 | 16/6/2026 | SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the (1) kw or (2) position parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 1.2% | — | Deerfield Website PRO | 31/12/2002 | 16/6/2026 | WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name. | |
| Modificada | Alta (7.5) | 7.0% | — | Oreilly Website Professional | 22/8/2001 | 16/6/2026 | O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character. | |
| Modificada | Media (5) | 1.6% | — | Oreilly Website PRO | 22/8/2001 | 16/6/2026 | Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory. | |
| Modificada | Alta (7.5) | 1.4% | — | Oreilly Website PRO | 20/10/2000 | 16/6/2026 | O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe. | |
| Modificada | Alta (10) | 13% | — | Oreilly Website Professional | 19/7/2000 | 16/6/2026 | Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" parameter. | |
| Modificada | Alta (10) | 5.3% | — | Oreilly Website Professional | 17/7/2000 | 16/6/2026 | Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header. |