Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.42% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 18/9/2025 | 17/6/2026 | A flaw has been found in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /check_profile.php. Executing manipulation of the argument profile_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.35% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 17/9/2025 | 25/9/2026 | A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This affects an unknown function of the file /print_reports_prev.php. Executing manipulation of the argument profile_id can lead to cross site scripting. It is possible to launch the attack remotely. The… | |
| Analizada | Baja (2.1) | 0.34% | — | Facebook-julykringcadayona Student Information System | 17/9/2025 | 25/9/2026 | A vulnerability has been found in itsourcecode Student Information System 1.0. The affected element is an unknown function of the file /leveledit1.php. Such manipulation of the argument level_id leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.4) | 0.22% | — | Carmelo Food Ordering Review System | 16/9/2025 | 17/6/2026 | code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information. | |
| Analizada | Media (5.4) | 0.22% | — | Carmelo Food Ordering Review System | 16/9/2025 | 17/6/2026 | code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. An attacker enters malicious JavaScript code as a username, which triggers the XSS vulnerability when the admin views user information, resulting in the disclosure of the admin's cookie information. | |
| Aplazada | Alta (7.5) | 0.43% | — | Vmware Spring SecurityAI | 16/9/2025 | 17/6/2026 | The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue when using @PreAuthorize and other method security annotations, resulting in an authorization bypass. Your… | |
| Aplazada | Alta (8.8) | 0.41% | — | Color-stringAI | 15/9/2025 | 17/6/2026 | color-string is a parser and generator for CSS color strings. On 8 September 2025, the npm publishing account for color-string was taken over after a phishing attack. Version 2.1.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect… | |
| Analizada | Baja (2.1) | 0.36% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 14/9/2025 | 17/6/2026 | A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /stc-log-keeper/check_profile.php of the component POST Request Handler. The manipulation of the argument profile_id results in cross site scripting. The attack… | |
| Analizada | Baja (2.1) | 0.34% | — | Oretnom23 Food Ordering Management System | 14/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Impacted is an unknown function of the file /routers/ticket-message.php. Such manipulation of the argument ticket_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and… | |
| Analizada | Media (5.5) | 0.53% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 9/9/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Alta (7.1) | 0.13% | — | Wordpress Error Monitoring BY BugsnagAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tom Longridge WordPress Error Monitoring by Bugsnag bugsnag allows Stored XSS.This issue affects WordPress Error Monitoring by Bugsnag: from n/a through <= 1.6.3. | |
| Aplazada | Alta (8.4) | 0.17% | — | Ratoc Systems Raid Monitoring ManagerAI | 5/9/2025 | 17/6/2026 | RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. | |
| Analizada | Media (5.5) | 0.45% | — | Oretnom23 Food Ordering Management System | 2/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the file /routers/register-router.php. Such manipulation of the argument phone leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly… | |
| Modificada | Alta (7.5) | 2.3% | 💥 PoC | Redhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+4 | 2/9/2025 | 6/10/2026 | A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol… | |
| Analizada | Media (5.5) | 0.41% | — | Facebook-julykringcadayona Student Information System | 30/8/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (5.5) | 0.53% | — | Janobe Bakeshop Online Ordering System | 29/8/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of the argument phonenumber results in sql injection. The attack is possible to be carried out remotely. The exploit has been made… | |
| Analizada | Media (6.9) | 0.11% | — | Oetiker BGP Monitoring | 28/8/2025 | 25/9/2026 | Improper Certificate Validation in Checkmk Exchange plugin BGP Monitoring allows attackers in MitM position to intercept traffic. | |
| Aplazada | Crítica (9.8) | 0.71% | 💥 PoC | Ringcentral CommunicationsAI | 28/8/2025 | 17/6/2026 | The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes. | |
| Aplazada | Media (5.5) | 0.46% | — | Request-filtering-agentAI | 25/8/2025 | 17/6/2026 | request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Versions 1.x.x and earlier contain a vulnerability where HTTPS requests to 127.0.0.1 bypass IP address filtering, while HTTP requests are correctly blocked. This allows attackers to potentially access… | |
| Aplazada | Alta (7.5) | 0.36% | — | SpringbootblogAI | 22/8/2025 | 17/6/2026 | Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication. | |
| Aplazada | Media (5.9) | 0.18% | — | Wp-ecommerce Recurring Paypal DonationsAI | 22/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations recurring-donation allows Stored XSS.This issue affects Recurring PayPal Donations: from n/a through <= 1.8. | |
| Aplazada | Alta (8.1) | 0.67% | — | Dahz KitringAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dahz Kitring kitring allows PHP Local File Inclusion.This issue affects Kitring: from n/a through <= 2.8. | |
| Aplazada | Baja (2.1) | 0.34% | — | Acrel Environmental Monitoring Cloud PlatformAI | 18/8/2025 | 17/6/2026 | A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/UploadNewsImg. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (2.1) | 0.34% | — | Fabian Simple Cafe Ordering System | 15/8/2025 | 17/6/2026 | A vulnerability was determined in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown functionality of the file /portal.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Alta (7.5) | 0.37% | — | Kamleshyadav WP Lead Capturing PagesAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in kamleshyadav WP Lead Capturing Pages leadcapture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Lead Capturing Pages: from n/a through < 2.6. |