Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
9809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Phpgurukul Online Course RegistrationAI | 8/4/2026 | 24/7/2026 | Se ha identificado una debilidad en PHPGurukul Online Course Registration 3.1. Esta vulnerabilidad afecta a código desconocido del archivo /check_availability.php. La ejecución de una manipulación del argumento cid puede conducir a inyección SQL. Es posible lanzar el ataque de forma remota. El exploit se ha puesto a… | |
| Aplazada | Media (5.3) | 0.28% | — | UnitechpayAI | 8/4/2026 | 24/7/2026 | Vulnerabilidad de autorización faltante en Unitech Web UnitechPay unitechpay-paiements-mobile-money permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a UnitechPay: desde n/a hasta <= 1.0.2. | |
| Aplazada | Media (6.5) | 0.22% | — | Publishpress Post ExpiratorAI | 8/4/2026 | 24/7/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en PublishPress Post Expirator post-expirator permite XSS Basado en DOM. Este problema afecta a Post Expirator: desde n/a hasta <= 4.9.4. | |
| Analizada | Crítica (9.6) | 0.32% | — | HPE Aruba Networking Private 5G Core | 7/4/2026 | 17/6/2026 | A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /admin/update-image1.php of the component Parameter Handler. The manipulation of the argument filename results in sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 17/6/2026 | A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 24/7/2026 | Se ha identificado una debilidad en PHPGurukul Online Shopping Portal Project 2.1. Esto afecta una parte desconocida del archivo /cancelorder.php del componente Gestor de Parámetros. Esta manipulación del argumento oid causa inyección SQL. El ataque puede ser iniciado remotamente. El exploit ha sido puesto a… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 24/7/2026 | Una vulnerabilidad de seguridad ha sido descubierta en PHPGurukul Online Shopping Portal Project 2.1. Este problema afecta a alguna funcionalidad desconocida del archivo /categorywise-products.php del componente Gestor de Parámetros. La manipulación del argumento cid resulta en inyección SQL. El ataque puede lanzarse… | |
| Aplazada | Media (5.3) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 24/7/2026 | Se ha descubierto un fallo de seguridad en PHPGurukul Online Shopping Portal Project 2.1. El elemento afectado es una función desconocida del archivo /order-details.php del componente Gestor de Parámetros. La manipulación del argumento orderid resulta en inyección SQL. Es posible lanzar el ataque de forma remota. | |
| Analizada | Alta (8.8) | 0.40% | — | Phpscriptsmall Advance Gift Shop PRO Script | 5/4/2026 | 24/7/2026 | Advance Gift Shop Pro Script 2.0.3 contiene una vulnerabilidad de inyección SQL que permite a atacantes no autenticados ejecutar consultas SQL arbitrarias inyectando código malicioso a través del parámetro de búsqueda. Los atacantes pueden enviar cargas útiles SQL manipuladas en el parámetro 's' de las solicitudes de… | |
| Analizada | Alta (8.8) | 0.46% | — | Phpscriptsmall ASK Expert Script | 5/4/2026 | 24/7/2026 | Ask Expert Script 3.0.5 contiene vulnerabilidades de cross-site scripting y de inyección SQL que permiten a atacantes no autenticados inyectar código malicioso manipulando los parámetros de la URL. Los atacantes pueden inyectar etiquetas de script a través del parámetro cateid en categorysearch.php o código SQL a… | |
| Analizada | Alta (8.8) | 0.40% | — | Phpscriptsmall News Website Script | 5/4/2026 | 24/7/2026 | Script de Sitio Web de Noticias 2.0.5 contiene una vulnerabilidad de inyección SQL que permite a atacantes no autenticados manipular consultas de base de datos inyectando código SQL a través del parámetro de ID de noticia. Los atacantes pueden enviar solicitudes GET a index.php/show/news/ con sentencias SQL maliciosas… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | Se ha detectado una vulnerabilidad de seguridad en PHPGurukul Online Shopping Portal Project 2.1. Esto afecta una parte desconocida del archivo /my-profile.php del componente Gestor de Parámetros. La manipulación del argumento fullname conduce a inyección SQL. Es posible iniciar el ataque de forma remota. El exploit… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | Una vulnerabilidad fue encontrada en PHPGurukul Online Shopping Portal Project 2.1. El elemento afectado es una función desconocida del archivo /payment-method.php del componente Gestor de Parámetros. Realizar una manipulación del argumento paymethod resulta en inyección SQL. Es posible iniciar el ataque remotamente.… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | Se ha encontrado una vulnerabilidad en el proyecto PHPGurukul PHPGurukul Online Shopping Portal hasta la versión 2.1. Afecta a una función desconocida del archivo /pending-orders.php del componente Gestor de Parámetros. Esta manipulación del argumento ID causa inyección SQL. El ataque puede ser llevado a cabo de forma… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | Se ha identificado una debilidad en PHPGurukul Online Shopping Portal Project 2.1. Este problema afecta a algún procesamiento desconocido del archivo /sub-category.php del componente Gestor de Parámetros. Esta manipulación del argumento pid causa inyección SQL. La explotación remota del ataque es posible. El exploit… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul User Registration & Login AND User Management SystemAI | 5/4/2026 | 24/7/2026 | Una vulnerabilidad fue identificada en PHPGurukul User Registration & Login and User Management System 3.3. El elemento afectado es una función desconocida del archivo /admin/yesterday-reg-users.php. La manipulación del argumento ID conduce a inyección SQL. La explotación remota del ataque es posible. El exploit está… | |
| Analizada | Media (5.4) | 0.26% | — | Phpmyfaq | 2/4/2026 | 24/7/2026 | phpMyFAQ es una aplicación web de preguntas frecuentes de código abierto. Antes de la versión 4.1.1, el saneador de SVG basado en expresiones regulares en phpMyFAQ (SvgSanitizer.php) puede ser eludido utilizando codificación de entidades HTML en URLs de tipo javascript: dentro de atributos <a href> de SVG. Cualquier… | |
| Analizada | Media (6.9) | 0.39% | — | Phpmyfaq | 2/4/2026 | 24/7/2026 | phpMyFAQ es una aplicación web de preguntas frecuentes de código abierto. Antes de la versión 4.1.1, el método searchCustomPages() en phpmyfaq/src/phpMyFAQ/Search.php utiliza real_escape_string() (a través de escape()) para sanear el término de búsqueda antes de incrustarlo en cláusulas LIKE. Sin embargo,… | |
| Analizada | Media (4.8) | 0.29% | — | Phpmyfaq | 2/4/2026 | 17/6/2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, there is a stored XSS vulnerability via Regex Bypass in Filter::removeAttributes(). This issue has been patched in version 4.1.1. | |
| Analizada | Alta (8.1) | 0.79% | — | Phpmyfaq | 2/4/2026 | 17/6/2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser. When the fileRemove action is triggered, the user-supplied name parameter is concatenated with the base upload directory path without any path traversal… | |
| Analizada | Media (5.4) | 0.30% | — | Phpmyfaq | 2/4/2026 | 17/6/2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that is syntactically valid per RFC 5321 (quoted local part) yet contains raw HTML — for example "<script>alert(1)</script>"@evil.com. PHP's FILTER_VALIDATE_EMAIL accepts… | |
| Analizada | Crítica (9.8) | 0.32% | — | Auth0-php | 1/4/2026 | 17/6/2026 | Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and forging session cookies. This issue has… | |
| Modificada | Media (6.1) | 0.31% | — | Pushpam02 ZOO Management System | 1/4/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerability is located in the login page, specifically within the msg parameter. The application reflects the content of the msg parameter back to the user without proper HTML encoding or sanitization. This… |