Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

3978 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.24%—Phpgurukul Online Shopping Portal25/11/202517/6/2026
Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.
AplazadaMedia (6.4)0.18%—Inline Frame IframeAI25/11/202517/6/2026
The Inline frame – Iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedsite' shortcode in all versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaBaja (2)0.32%—Senior-walter Online Student Clearance System24/11/20258/10/2026
Se ha encontrado una vulnerabilidad en SourceCodester Online Student Clearance System 1.0. Afecta a una función desconocida del archivo /Admin/changepassword.PHP. Esta manipulación del argumento txtconfirm_password causa inyección SQL. Es posible iniciar el ataque de forma remota. El exploit ha sido publicado y puede…
AnalizadaBaja (2)0.39%—Fabian Online Bidding System23/11/20258/10/2026
Se ha identificado una debilidad en el sistema de subastas en línea code-projects Online Bidding System 1.0. Este problema afecta la función categoryadd del archivo /administrator/addcategory.PHP. Esta manipulación del argumento catimage causa una carga sin restricciones. El ataque es posible de realizar de forma…
AnalizadaMedia (5.5)0.39%—Campcodes Online Polling System23/11/202517/6/2026
A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
ModificadaMedia (5.5)0.39%—Campcodes Online Polling System23/11/202517/6/2026
A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing a manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
AnalizadaCrítica (9.8)1.1%—Microsoft Sharepoint Online20/11/202517/6/2026
Microsoft SharePoint Online Elevation of Privilege Vulnerability
ModificadaBaja (1.9)0.25%—Campcodes Online Beauty Parlor Management System20/11/202517/6/2026
A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/customer-list.php. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and…
AnalizadaMedia (5.5)0.40%—Oretnom23 Online Shop Project20/11/202517/6/2026
A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
AnalizadaBaja (2)0.24%—Oretnom23 Online Shop Project20/11/202517/6/2026
A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /shop/register.php. This manipulation of the argument f_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (5.5)0.40%—Oretnom23 Online Shop Project20/11/202517/6/2026
A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
ModificadaBaja (2)0.34%—Campcodes Retro Basketball Shoes Online Store20/11/202517/6/2026
A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and…
AnalizadaAlta (7.3)0.20%—Campcodes Online Hospital Management System19/11/202517/6/2026
Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter username.
ModificadaBaja (1.9)0.25%—Campcodes Retro Basketball Shoes Online Store19/11/202517/6/2026
A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing a manipulation of the argument product_name can lead to cross site scripting. The attack may be performed from remote. The exploit…
ModificadaBaja (2)0.36%—Campcodes Retro Basketball Shoes Online Store19/11/202517/6/2026
A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing a manipulation of the argument product_image results in unrestricted upload. The attack is possible to be carried out remotely.…
AnalizadaMedia (5.5)0.39%—Campcodes Retro Basketball Shoes Online Store19/11/202517/6/2026
A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of the file /admin/receipt.php. Such manipulation of the argument tid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
AplazadaAlta (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2819/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
AplazadaAlta (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2819/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.
AnalizadaMedia (5.4)0.22%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.
AnalizadaCrítica (9.8)0.41%—Phpgurukul Online Shopping Portal17/11/202528/9/2026
El Portal de Compras en Línea PHPGurukul 2.0 es vulnerable a inyección SQL a través del parámetro 'email' en forgot-password.php.
AnalizadaBaja (2.1)0.33%—Angeljudesuarez Online Voting System17/11/20257/10/2026
Se ha identificado una debilidad en itsourcecode Online Voting System 1.0. Esto afecta una función desconocida del archivo /index.php?page=categories. La ejecución de manipulación del argumento id/category puede llevar a inyección SQL. El ataque puede ser ejecutado remotamente. El exploit ha sido puesto a disposición…