Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.29% | — | Yzcheng90 X-springboot | 4/12/2025 | 17/6/2026 | This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (RBAC) through dual dependency on frontend menu systems and backend permission tables, without enforcing atomic synchronization between these components. The critical flaw manifests when frontend menu… | |
| Analizada | Baja (2.1) | 0.31% | — | Facebook-julykringcadayona Student Information System | 24/11/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /schedule_edit1.php. Such manipulation of the argument schedule_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and… | |
| Analizada | Baja (2.1) | 0.31% | — | Fabian Simple Cafe Ordering System | 23/11/2025 | 17/6/2026 | A vulnerability was determined in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /listorder.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Crítica (9.8) | 0.33% | — | Eksagate Electronic Engineering AND Computer Industry Trade INC Webpack Management SystemAI | 19/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows SQL Injection. This issue affects Webpack Management System: through 20251119. | |
| Analizada | Baja (2.1) | 0.31% | — | Facebook-julykringcadayona Student Information System | 18/11/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /enrollment_edit1.php. Executing manipulation of the argument en_id can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may… | |
| Analizada | Media (5.5) | 0.44% | — | Carmelo Simple Pizza Ordering System | 18/11/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /listorder.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. | |
| Analizada | Baja (2.1) | 0.31% | — | Fabian Simple Food Ordering System | 17/11/2025 | 7/10/2026 | A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /saveorder.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Simple Cafe Ordering System | 15/11/2025 | 7/10/2026 | A weakness has been identified in code-projects Simple Cafe Ordering System 1.0. This vulnerability affects unknown code of the file /addmem.php. Executing manipulation of the argument studentnum can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public… | |
| Analizada | Baja (2) | 0.26% | — | Fabian Simple Cafe Ordering System | 15/11/2025 | 7/10/2026 | A security flaw has been discovered in code-projects Simple Cafe Ordering System 1.0. This affects an unknown part of the file /add_to_cart. Performing manipulation of the argument product_name results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public… | |
| Analizada | Media (5.5) | 0.46% | — | Fabian Simple Cafe Ordering System | 15/11/2025 | 7/10/2026 | A vulnerability was identified in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Username leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.32% | — | Janobe Food Ordering System | 10/11/2025 | 7/10/2026 | A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/edit-orders.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could… | |
| Analizada | Baja (2.1) | 0.32% | — | Janobe Food Ordering System | 10/11/2025 | 7/10/2026 | A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /view-ticket.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Baja (2.1) | 0.36% | — | Projectworlds Online Notes Sharing Platform | 7/11/2025 | 7/10/2026 | A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be performed from remote. The exploit is publicly… | |
| Aplazada | Media (5.3) | 0.31% | — | Amazon Research AND Engineering StudioAI | 6/11/2025 | 7/10/2026 | An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots. To mitigate this issue, users… | |
| Aplazada | Crítica (9.8) | 0.44% | — | Holest Engineering Selling Commander FOR WoocommerceAI | 6/11/2025 | 7/10/2026 | Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-connector allows Privilege Escalation.This issue affects Selling Commander for WooCommerce: from n/a through <= 1.2.46. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Easy Upload Files During CheckoutAI | 4/11/2025 | 17/6/2026 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in the 'file_during_checkout' function in all versions up to, and including, 2.9.8. This makes it possible for unauthenticated attackers to upload arbitrary JavaScript files… | |
| Analizada | Media (5.4) | 0.25% | 💥 PoC | Phpgurukul Maid Hiring Management System | 3/11/2025 | 17/6/2026 | Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field. | |
| Analizada | Crítica (9.8) | 0.42% | — | IBM Tivoli Monitoring | 30/10/2025 | 7/10/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system. | |
| Analizada | Alta (7.5) | 0.53% | — | IBM Tivoli Monitoring | 30/10/2025 | 7/10/2026 | IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Aplazada | Alta (8.2) | 0.32% | 💥 PoC | SPH Engineering UgcsAI | 29/10/2025 | 17/6/2026 | SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution. | |
| Aplazada | Alta (7.5) | 0.26% | — | Blog-vue-springbootAI | 28/10/2025 | 17/6/2026 | Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot. | |
| Analizada | Media (5.5) | 0.53% | — | Fabian Simple Food Ordering System | 28/10/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addproduct.php. Performing manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public… | |
| Modificada | Baja (2) | 0.41% | — | Code-projects Food Ordering System | 27/10/2025 | 17/6/2026 | A vulnerability was determined in code-projects Food Ordering System 1.0. This affects an unknown function of the file /admin/menu.php. Executing a manipulation of the argument itemPrice can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. | |
| Modificada | Baja (2) | 0.36% | — | Code-projects Food Ordering System | 27/10/2025 | 17/6/2026 | A vulnerability was found in code-projects Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/deleteitem.php. Performing a manipulation of the argument itemID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be… | |
| Analizada | Baja (2.1) | 0.39% | — | Fabian Simple Food Ordering System | 27/10/2025 | 17/6/2026 | A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown function of the file /editproduct.php. Performing manipulation of the argument pname/category/price results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may… |