Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3005 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.24%—Phpgurukul Online Shopping Portal25/11/202517/6/2026
Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.
AnalizadaBaja (2)0.32%—Senior-walter Online Student Clearance System24/11/20258/10/2026
Se ha encontrado una vulnerabilidad en SourceCodester Online Student Clearance System 1.0. Afecta a una función desconocida del archivo /Admin/changepassword.PHP. Esta manipulación del argumento txtconfirm_password causa inyección SQL. Es posible iniciar el ataque de forma remota. El exploit ha sido publicado y puede…
AnalizadaBaja (2)0.39%—Fabian Online Bidding System23/11/20258/10/2026
Se ha identificado una debilidad en el sistema de subastas en línea code-projects Online Bidding System 1.0. Este problema afecta la función categoryadd del archivo /administrator/addcategory.PHP. Esta manipulación del argumento catimage causa una carga sin restricciones. El ataque es posible de realizar de forma…
AnalizadaMedia (5.5)0.39%—Campcodes Online Polling System23/11/202517/6/2026
A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
ModificadaMedia (5.5)0.39%—Campcodes Online Polling System23/11/202517/6/2026
A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing a manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
AnalizadaCrítica (9.8)1.1%—Microsoft Sharepoint Online20/11/202517/6/2026
Microsoft SharePoint Online Elevation of Privilege Vulnerability
ModificadaBaja (1.9)0.25%—Campcodes Online Beauty Parlor Management System20/11/202517/6/2026
A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/customer-list.php. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and…
AnalizadaMedia (5.5)0.40%—Oretnom23 Online Shop Project20/11/202517/6/2026
A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
AnalizadaBaja (2)0.24%—Oretnom23 Online Shop Project20/11/202517/6/2026
A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /shop/register.php. This manipulation of the argument f_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (5.5)0.40%—Oretnom23 Online Shop Project20/11/202517/6/2026
A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
ModificadaBaja (2)0.34%—Campcodes Retro Basketball Shoes Online Store20/11/202517/6/2026
A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and…
AnalizadaAlta (7.3)0.20%—Campcodes Online Hospital Management System19/11/202517/6/2026
Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter username.
ModificadaBaja (1.9)0.25%—Campcodes Retro Basketball Shoes Online Store19/11/202517/6/2026
A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing a manipulation of the argument product_name can lead to cross site scripting. The attack may be performed from remote. The exploit…
ModificadaBaja (2)0.36%—Campcodes Retro Basketball Shoes Online Store19/11/202517/6/2026
A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing a manipulation of the argument product_image results in unrestricted upload. The attack is possible to be carried out remotely.…
AnalizadaMedia (5.5)0.39%—Campcodes Retro Basketball Shoes Online Store19/11/202517/6/2026
A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of the file /admin/receipt.php. Such manipulation of the argument tid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.
AnalizadaMedia (5.4)0.22%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.
AnalizadaCrítica (9.8)0.41%—Phpgurukul Online Shopping Portal17/11/202528/9/2026
El Portal de Compras en Línea PHPGurukul 2.0 es vulnerable a inyección SQL a través del parámetro 'email' en forgot-password.php.
AnalizadaBaja (2.1)0.33%—Angeljudesuarez Online Voting System17/11/20257/10/2026
Se ha identificado una debilidad en itsourcecode Online Voting System 1.0. Esto afecta una función desconocida del archivo /index.php?page=categories. La ejecución de manipulación del argumento id/category puede llevar a inyección SQL. El ataque puede ser ejecutado remotamente. El exploit ha sido puesto a disposición…
AnalizadaBaja (2.1)0.31%—Angeljudesuarez Online Voting System17/11/20257/10/2026
Se ha descubierto una falla de seguridad en itsourcecode Online Voting System 1.0. El elemento afectado es una función desconocida del archivo /ajax.PHP?action=save_user. La manipulación del argumento ID resulta en inyección SQL. La explotación remota del ataque es posible. El exploit ha sido publicado y puede ser…
AnalizadaMedia (5.5)0.41%—Angeljudesuarez Online Voting System17/11/20257/10/2026
Una vulnerabilidad fue identificada en itsourcecode Online Voting System 1.0. El elemento afectado es una función desconocida del archivo /login.php. Tal manipulación del argumento Username lleva a inyección SQL. El ataque puede ser lanzado remotamente. El exploit está disponible públicamente y podría ser usado.
AplazadaMedia (5.5)0.30%—G33kyrash Online-banking-systemAI17/11/20257/10/2026
Una vulnerabilidad fue detectada en el sistema de banca en línea g33kyrash hasta 12dbfa690e5af649fb72d2e5d3674e88d6743455. Esta vulnerabilidad afecta código desconocido del archivo /index.php. La manipulación del argumento Username resulta en inyección SQL. Es posible lanzar el ataque remotamente. El exploit ahora es…