Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.29%—Yzcheng90 X-springboot4/12/202517/6/2026
This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (RBAC) through dual dependency on frontend menu systems and backend permission tables, without enforcing atomic synchronization between these components. The critical flaw manifests when frontend menu…
AnalizadaBaja (2.1)0.31%—Facebook-julykringcadayona Student Information System24/11/202517/6/2026
A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /schedule_edit1.php. Such manipulation of the argument schedule_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and…
AnalizadaBaja (2.1)0.31%—Fabian Simple Cafe Ordering System23/11/202517/6/2026
A vulnerability was determined in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /listorder.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be…
AplazadaCrítica (9.8)0.33%—Eksagate Electronic Engineering AND Computer Industry Trade INC Webpack Management SystemAI19/11/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows SQL Injection. This issue affects Webpack Management System: through 20251119.
AnalizadaBaja (2.1)0.31%—Facebook-julykringcadayona Student Information System18/11/202517/6/2026
A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_edit1.php. Executing manipulation of the argument en_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may…
AnalizadaMedia (5.5)0.44%—Carmelo Simple Pizza Ordering System18/11/202517/6/2026
A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /listorder.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited.
AnalizadaBaja (2.1)0.31%—Fabian Simple Food Ordering System17/11/20257/10/2026
A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /saveorder.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (5.5)0.39%—Fabian Simple Cafe Ordering System15/11/20257/10/2026
A weakness has been identified in code-projects Simple Cafe Ordering System 1.0. This vulnerability affects unknown code of the file /addmem.php. Executing manipulation of the argument studentnum can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public…
AnalizadaBaja (2)0.26%—Fabian Simple Cafe Ordering System15/11/20257/10/2026
A security flaw has been discovered in code-projects Simple Cafe Ordering System 1.0. This affects an unknown part of the file /add_to_cart. Performing manipulation of the argument product_name results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public…
AnalizadaMedia (5.5)0.46%—Fabian Simple Cafe Ordering System15/11/20257/10/2026
A vulnerability was identified in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Username leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
AnalizadaBaja (2.1)0.32%—Janobe Food Ordering System10/11/20257/10/2026
A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/edit-orders.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could…
AnalizadaBaja (2.1)0.32%—Janobe Food Ordering System10/11/20257/10/2026
A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /view-ticket.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
ModificadaBaja (2.1)0.36%—Projectworlds Online Notes Sharing Platform7/11/20257/10/2026
A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be performed from remote. The exploit is publicly…
AplazadaMedia (5.3)0.31%—Amazon Research AND Engineering StudioAI6/11/20257/10/2026
An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots. To mitigate this issue, users…
AplazadaCrítica (9.8)0.44%—Holest Engineering Selling Commander FOR WoocommerceAI6/11/20257/10/2026
Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-connector allows Privilege Escalation.This issue affects Selling Commander for WooCommerce: from n/a through <= 1.2.46.
AplazadaCrítica (9.8)0.65%—Easy Upload Files During CheckoutAI4/11/202517/6/2026
The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in the 'file_during_checkout' function in all versions up to, and including, 2.9.8. This makes it possible for unauthenticated attackers to upload arbitrary JavaScript files…
AnalizadaMedia (5.4)0.25%💥 PoCPhpgurukul Maid Hiring Management System3/11/202517/6/2026
Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.
AnalizadaCrítica (9.8)0.42%—IBM Tivoli Monitoring30/10/20257/10/2026
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system.
AnalizadaAlta (7.5)0.53%—IBM Tivoli Monitoring30/10/20257/10/2026
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
AplazadaAlta (8.2)0.32%💥 PoCSPH Engineering UgcsAI29/10/202517/6/2026
SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution.
AplazadaAlta (7.5)0.26%—Blog-vue-springbootAI28/10/202517/6/2026
Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot.
AnalizadaMedia (5.5)0.53%—Fabian Simple Food Ordering System28/10/202517/6/2026
A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addproduct.php. Performing manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public…
ModificadaBaja (2)0.41%—Code-projects Food Ordering System27/10/202517/6/2026
A vulnerability was determined in code-projects Food Ordering System 1.0. This affects an unknown function of the file /admin/menu.php. Executing a manipulation of the argument itemPrice can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
ModificadaBaja (2)0.36%—Code-projects Food Ordering System27/10/202517/6/2026
A vulnerability was found in code-projects Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/deleteitem.php. Performing a manipulation of the argument itemID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be…
AnalizadaBaja (2.1)0.39%—Fabian Simple Food Ordering System27/10/202517/6/2026
A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown function of the file /editproduct.php. Performing manipulation of the argument pname/category/price results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may…