Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.47% | — | Wpjobportal WP JOB Portal | 14/12/2024 | 17/6/2026 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'ff' parameter of the getFieldsForVisibleCombobox() function in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lack of… | |
| Analizada | Media (4.9) | 0.47% | — | Wpjobportal WP JOB Portal | 14/12/2024 | 17/6/2026 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'page_id' parameter of the wpjobportal_deactivate() function in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lack of… | |
| Analizada | Media (5.3) | 0.47% | — | Wpjobportal WP JOB Portal | 14/12/2024 | 17/6/2026 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated… | |
| Analizada | Alta (7.5) | 0.52% | — | Wpjobportal WP JOB Portal | 14/12/2024 | 17/6/2026 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'resumeid' parameter in all versions up to, and including, 2.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Analizada | Media (4.9) | 0.47% | — | Wpjobportal WP JOB Portal | 14/12/2024 | 17/6/2026 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'fieldfor', 'visibleParent' and 'id' parameters in all versions up to, and including, 2.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Modificada | Media (5.4) | 0.26% | — | Wpjobportal WP JOB Portal | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpjobportal WP Job Portal wp-job-portal allows Stored XSS.This issue affects WP Job Portal: from n/a through <= 2.2.0. | |
| Analizada | Media (6.1) | 0.28% | — | Phpgurukul JOB Portal | 5/9/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through user_email parameter in /jobportal/admin/login.php. | |
| Analizada | Media (6.1) | 0.28% | — | Phpgurukul JOB Portal | 5/9/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through multiple parameters in /jobportal/index.php. | |
| Analizada | Media (6.1) | 0.25% | — | Phpgurukul JOB Portal | 5/9/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through JOBID and USERNAME parameters in /jobportal/process.php. | |
| Analizada | Alta (7.5) | 0.46% | — | Phpgurukul JOB Portal | 5/9/2024 | 17/6/2026 | SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in it. | |
| Analizada | Alta (7.5) | 0.46% | — | Phpgurukul JOB Portal | 5/9/2024 | 17/6/2026 | SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in it. | |
| Analizada | Alta (7.5) | 0.46% | — | Phpgurukul JOB Portal | 5/9/2024 | 17/6/2026 | SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in it. | |
| Analizada | Alta (7.5) | 0.46% | — | Phpgurukul JOB Portal | 5/9/2024 | 17/6/2026 | SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in it. | |
| Analizada | Alta (7.5) | 0.46% | — | Phpgurukul JOB Portal | 5/9/2024 | 17/6/2026 | SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in it. | |
| Analizada | Alta (7.5) | 0.46% | 💥 PoC | Phpgurukul JOB Portal | 5/9/2024 | 17/6/2026 | SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in it. | |
| Analizada | Alta (7.5) | 0.46% | — | Phpgurukul JOB Portal | 5/9/2024 | 17/6/2026 | SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in it. | |
| Analizada | Alta (8.8) | 0.51% | — | Phpgurukul JOB Portal | 5/9/2024 | 17/6/2026 | File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell. | |
| Analizada | Crítica (9.8) | 1.2% | — | Wpjobportal WP JOB Portal | 4/9/2024 | 17/6/2026 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary Settings Update, and User Creation in all versions up to, and including, 2.1.6 via several functions called by the 'checkFormRequest' function. This makes it possible… | |
| Analizada | Media (6.9) | 0.65% | — | Fabian JOB Portal | 26/8/2024 | 17/6/2026 | A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /forget.php. The manipulation of the argument email/mobile leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (8.8) | 0.36% | — | Wpjobportal WP JOB Portal | 18/8/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue affects WP Job Portal: from n/a through <= 2.1.8. | |
| Analizada | Media (6.9) | 1.2% | 💥 PoC | Fabian JOB Portal | 15/8/2024 | 17/6/2026 | A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file logindbc.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.9) | 0.66% | — | Fabian JOB Portal | 12/8/2024 | 17/6/2026 | A vulnerability was found in code-projects Job Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file rw_i_nat.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (4.8) | 0.32% | — | Wpjobportal WP JOB Portal | 21/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpjobportal WP Job Portal wp-job-portal allows DOM-Based XSS.This issue affects WP Job Portal: from n/a through <= 2.1.3. | |
| Modificada | Media (4.8) | 0.28% | — | Wpjobportal WP JOB Portal | 21/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue affects WP Job Portal: from n/a through <= 2.1.3. | |
| Analizada | Media (5.5) | 0.31% | — | Code-projects Online JOB Portal | 7/3/2024 | 17/6/2026 | code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1. |