Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

165 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.28%—Agilelogix Free Google MapsAI15/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agile Logix Free Google Maps wp-map allows Stored XSS.This issue affects Free Google Maps: from n/a through <= 1.0.1.
AnalizadaMedia (6.9)0.65%—Carmelogarcia Restaurant Order System3/11/202417/6/2026
A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public…
AnalizadaMedia (6.9)0.70%—Carmelogarcia Courier Management System1/11/202417/6/2026
A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument txtusername leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.70%—Carmelogarcia Courier Management System1/11/202417/6/2026
A vulnerability was found in code-projects Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /track-result.php. The manipulation of the argument Consignment leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…
AnalizadaCrítica (9.3)3.8%⚠ Explotación activaSciencelogic SL118/10/202417/6/2026
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x,…
AnalizadaCrítica (9.8)0.66%—Wavelog14/10/202417/6/2026
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
ModificadaCrítica (9.8)0.55%—Wavelog14/10/202417/6/2026
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
AnalizadaAlta (7.3)0.43%—Wavelog14/10/202417/6/2026
Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
AplazadaMedia (6.4)0.27%—RelogoAI1/10/202417/6/2026
The Relogo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web…
ModificadaCrítica (9.8)11%💥 PoCOnelogin Ruby-samlOmniauth SamlGitlab10/9/202417/6/2026
The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with…
AnalizadaMedia (6.9)0.57%—Wavelog7/9/202417/6/2026
A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the component Live QSO. The manipulation of the argument manual leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (6.4)0.11%—Schneider-electric Spacelogic As-b FirmwareSchneider-electric Spacelogic As-p Firmware12/6/202417/6/2026
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.
ModificadaMedia (4.5)0.23%—Schneider-electric Spacelogic As-b FirmwareSchneider-electric Spacelogic As-p Firmware12/6/202417/6/2026
CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause exposure of SNMP credentials when an attacker has access to the controller logs.
AplazadaMedia (6.8)0.62%—Agilelogix Store LocatorAI18/4/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AGILELOGIX Store Locator WordPress.This issue affects Store Locator WordPress: from n/a through 1.4.14.
ModificadaMedia (6.1)0.43%—Carmelogarcia Employee Profile Management System12/1/202417/6/2026
A vulnerability, which was classified as problematic, was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_position_query.php. The manipulation of the argument pos_name leads to cross site scripting. It is possible to launch the attack remotely. The…
ModificadaCrítica (9.8)0.50%—Carmelogarcia Faculty Management System12/1/202417/6/2026
A vulnerability was found in code-projects Faculty Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/pages/student-print.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
ModificadaAlta (8.8)0.74%—Carmelogarcia College Notes Gallery31/12/202317/6/2026
A vulnerability has been found in code-projects College Notes Gallery 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument user leads to sql injection. The exploit has been disclosed to the public and may be used. The…
ModificadaMedia (5.4)0.61%—Carmelogarcia Intern Membership Management System28/12/202317/6/2026
A vulnerability was found in code-projects Intern Membership Management System 2.0. It has been classified as problematic. This affects an unknown part of the file /user_registration/ of the component User Registration. The manipulation of the argument userName/firstName/lastName/userEmail with the input…
ModificadaCrítica (9.8)0.72%—Carmelogarcia Intern Membership Management System28/12/202317/6/2026
A vulnerability was found in code-projects Intern Membership Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user_registration/ of the component User Registration. The manipulation of the argument userName leads to sql injection. The exploit has been…
ModificadaBaja (2)0.67%—Carmelogarcia Faculty Management System25/12/202317/6/2026
A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the file /admin/php/crud.php. This manipulation of the argument fieldname/tablename causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be…
ModificadaMedia (6.1)0.51%—Carmelogarcia Faculty Management System22/12/202317/6/2026
A vulnerability, which was classified as problematic, has been found in code-projects Faculty Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/pages/yearlevel.php. The manipulation of the argument Year Level/Section leads to cross site scripting. The attack may be launched…
ModificadaMedia (5.4)0.49%—Carmelogarcia Faculty Management System22/12/202317/6/2026
A vulnerability classified as problematic was found in code-projects Faculty Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/pages/subjects.php. The manipulation of the argument Description/Units leads to cross site scripting. The attack can be launched remotely.…
ModificadaCrítica (9.8)0.86%—Carmelogarcia Matrimonial Site10/12/202317/6/2026
A vulnerability was found in code-projects Matrimonial Site 1.0. It has been declared as critical. Affected by this vulnerability is the function register of the file /register.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be…
ModificadaCrítica (9.8)0.86%—Carmelogarcia Matrimonial Site10/12/202317/6/2026
A vulnerability was found in code-projects Matrimonial Site 1.0. It has been classified as critical. Affected is an unknown function of the file /auth/auth.php?user=1. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaAlta (8.8)0.31%—Wielogorski Stop Referrer Spam13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Krzysztof Wielogórski Stop Referrer Spam plugin <= 1.3.0 versions.
Orbitaley — Vulnerabilidades