Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3005 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.24% | — | Phpgurukul Online Shopping Portal | 25/11/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter. | |
| Analizada | Baja (2) | 0.32% | — | Senior-walter Online Student Clearance System | 24/11/2025 | 8/10/2026 | Se ha encontrado una vulnerabilidad en SourceCodester Online Student Clearance System 1.0. Afecta a una función desconocida del archivo /Admin/changepassword.PHP. Esta manipulación del argumento txtconfirm_password causa inyección SQL. Es posible iniciar el ataque de forma remota. El exploit ha sido publicado y puede… | |
| Analizada | Baja (2) | 0.39% | — | Fabian Online Bidding System | 23/11/2025 | 8/10/2026 | Se ha identificado una debilidad en el sistema de subastas en línea code-projects Online Bidding System 1.0. Este problema afecta la función categoryadd del archivo /administrator/addcategory.PHP. Esta manipulación del argumento catimage causa una carga sin restricciones. El ataque es posible de realizar de forma… | |
| Analizada | Media (5.5) | 0.39% | — | Campcodes Online Polling System | 23/11/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (5.5) | 0.39% | — | Campcodes Online Polling System | 23/11/2025 | 17/6/2026 | A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing a manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. | |
| Analizada | Crítica (9.8) | 1.1% | — | Microsoft Sharepoint Online | 20/11/2025 | 17/6/2026 | Microsoft SharePoint Online Elevation of Privilege Vulnerability | |
| Modificada | Baja (1.9) | 0.25% | — | Campcodes Online Beauty Parlor Management System | 20/11/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/customer-list.php. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and… | |
| Analizada | Media (5.5) | 0.40% | — | Oretnom23 Online Shop Project | 20/11/2025 | 17/6/2026 | A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2) | 0.24% | — | Oretnom23 Online Shop Project | 20/11/2025 | 17/6/2026 | A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /shop/register.php. This manipulation of the argument f_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.40% | — | Oretnom23 Online Shop Project | 20/11/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Modificada | Baja (2) | 0.34% | — | Campcodes Retro Basketball Shoes Online Store | 20/11/2025 | 17/6/2026 | A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and… | |
| Analizada | Alta (7.3) | 0.20% | — | Campcodes Online Hospital Management System | 19/11/2025 | 17/6/2026 | Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter username. | |
| Modificada | Baja (1.9) | 0.25% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing a manipulation of the argument product_name can lead to cross site scripting. The attack may be performed from remote. The exploit… | |
| Modificada | Baja (2) | 0.36% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing a manipulation of the argument product_image results in unrestricted upload. The attack is possible to be carried out remotely.… | |
| Analizada | Media (5.5) | 0.39% | — | Campcodes Retro Basketball Shoes Online Store | 19/11/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of the file /admin/receipt.php. Such manipulation of the argument tid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php. | |
| Analizada | Media (5.4) | 0.22% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php. | |
| Analizada | Crítica (9.8) | 0.41% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 28/9/2026 | El Portal de Compras en Línea PHPGurukul 2.0 es vulnerable a inyección SQL a través del parámetro 'email' en forgot-password.php. | |
| Analizada | Baja (2.1) | 0.33% | — | Angeljudesuarez Online Voting System | 17/11/2025 | 7/10/2026 | Se ha identificado una debilidad en itsourcecode Online Voting System 1.0. Esto afecta una función desconocida del archivo /index.php?page=categories. La ejecución de manipulación del argumento id/category puede llevar a inyección SQL. El ataque puede ser ejecutado remotamente. El exploit ha sido puesto a disposición… | |
| Analizada | Baja (2.1) | 0.31% | — | Angeljudesuarez Online Voting System | 17/11/2025 | 7/10/2026 | Se ha descubierto una falla de seguridad en itsourcecode Online Voting System 1.0. El elemento afectado es una función desconocida del archivo /ajax.PHP?action=save_user. La manipulación del argumento ID resulta en inyección SQL. La explotación remota del ataque es posible. El exploit ha sido publicado y puede ser… | |
| Analizada | Media (5.5) | 0.41% | — | Angeljudesuarez Online Voting System | 17/11/2025 | 7/10/2026 | Una vulnerabilidad fue identificada en itsourcecode Online Voting System 1.0. El elemento afectado es una función desconocida del archivo /login.php. Tal manipulación del argumento Username lleva a inyección SQL. El ataque puede ser lanzado remotamente. El exploit está disponible públicamente y podría ser usado. | |
| Aplazada | Media (5.5) | 0.30% | — | G33kyrash Online-banking-systemAI | 17/11/2025 | 7/10/2026 | Una vulnerabilidad fue detectada en el sistema de banca en línea g33kyrash hasta 12dbfa690e5af649fb72d2e5d3674e88d6743455. Esta vulnerabilidad afecta código desconocido del archivo /index.php. La manipulación del argumento Username resulta en inyección SQL. Es posible lanzar el ataque remotamente. El exploit ahora es… |