Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

164 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.36%—Vishalmathur Institute-of-current-studentsAI1/8/202517/6/2026
Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The myds GET parameter accepts an email address as input and directly returns the corresponding student's personal information without validating the identity or permissions of the requesting user. This…
AplazadaMedia (6.1)0.19%—Vishalmathur Institute-of-current-studentsAI1/8/202517/6/2026
A stored Cross-Site Scripting (XSS) vulnerability exists in the qureydetails.php page of Institute-of-Current-Students 1.0, where the input fields for Query and Answer do not properly sanitize user input. Authenticated users can inject arbitrary JavaScript code.
AplazadaMedia (6.5)0.24%—Vishalmathur Cloudclassroom-php-projectAI1/8/202517/6/2026
A SQL Injection vulnerability exists in the takeassessment2.php file of CloudClassroom-PHP-Project 1.0. The Q4 POST parameter is not properly sanitized before being used in SQL queries.
AnalizadaMedia (6.1)0.27%—Vishalmathur Cloudclassroom31/7/202517/6/2026
CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the postquerypublic endpoint. Improper sanitization allows an attacker to inject arbitrary JavaScript code that executes in the context of the user s browser, potentially leading to session hijacking…
AnalizadaMedia (6.5)0.24%—Vishalmathur Cloudclassroom31/7/202517/6/2026
A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.
ModificadaMedia (6.5)0.30%—Vishalmathur Cloudclassroom-php Project25/7/20255/7/2026
CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter.
AnalizadaMedia (6.1)0.32%—Vishalmathur Institute-of-current-students25/7/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in Institute-of-Current-Students v1.0 via the email parameter in the /postquerypublic endpoint. The application fails to properly sanitize user input before reflecting it in the HTML response. This allows unauthenticated attackers to inject and execute…
AplazadaMedia (6.5)0.30%—NET DropbearAILibtommathAI16/7/202517/6/2026
Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net::Dropbear embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.
AnalizadaAlta (7)0.43%—Devrafalko String-math30/6/202517/6/2026
string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.
AnalizadaCrítica (9.8)0.59%—Vishalmathur Cloudclassroom-php Project20/6/202517/6/2026
A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx parameter accepts unsanitized input, which is passed directly into backend SQL queries.
AplazadaAlta (8.1)0.52%—Powsybl-mathAI20/6/202517/6/2026
PowSyBl (Power System Blocks) is a framework to build power system oriented software. In versions 6.3.0 to 6.7.1, there is a deserialization issue in the read method of the SparseMatrix class that can lead to a wide range of privilege escalations depending on the circumstances. This method takes in an InputStream and…
AnalizadaCrítica (9.8)0.57%—Vishalmathur Cloudclassroom-php Project18/6/202517/6/2026
CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote attacker with access to the same network…
AnalizadaCrítica (9.8)0.63%—Vishalmathur Cloudclassroom-php Project18/6/202517/6/2026
CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails to sanitize user-supplied input in the admin login form before directly including it in SQL queries. This allows unauthenticated attackers to inject arbitrary SQL payloads and…
AplazadaCrítica (9.8)0.54%—Perl CryptxAILibtommathAI11/6/202517/6/2026
Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.
AnalizadaMedia (6.1)0.39%—Vishalmathur Cloudclassroom-php Project9/6/202517/6/2026
Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session hijacking or defacement.
AnalizadaAlta (7.3)1.1%—Vishalmathur Cloudclassroom-php Project2/6/202517/6/2026
SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to improper input validation, allowing attackers to inject SQL queries.
AnalizadaAlta (7.3)0.24%—Vishalmathur Cloudclassroom-php Project2/6/202517/6/2026
A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands.
AplazadaAlta (8.7)0.48%—Phpoffice MathAI30/5/202517/6/2026
PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data using the standard `libxml` extension and the `LIBXML_DTDLOAD` flag without additional filtration, leads to XXE. Version 0.3.0 fixes the vulnerability.
AplazadaAlta (7.1)0.19%—Mathieu Chartier Wp-planificationAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WP-Planification wp-planification allows Stored XSS.This issue affects WP-Planification: from n/a through <= 2.3.1.
AplazadaMedia (6.3)0.58%—Arnog MathliveAI1/4/202517/6/2026
Cross Site Scripting vulnerability in arnog MathLive Versions v0.103.0 and before (fixed in 0.104.0) allows an attacker to execute arbitrary code via the MathLive function.
ModificadaCrítica (9.8)0.49%—Jwpegram Block Spam BY Math Reloaded11/3/202517/6/2026
Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded block-spam-by-math-reloaded allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Block Spam By Math Reloaded: from n/a through <= 2.2.4.
ModificadaMedia (4.8)0.29%—Jwpegram Block Spam BY Math Reloaded11/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jwpegram Block Spam By Math Reloaded block-spam-by-math-reloaded allows Stored XSS.This issue affects Block Spam By Math Reloaded: from n/a through <= 2.2.4.
AnalizadaMedia (6.1)0.49%—Vishalmathur Cloudclassroom-php Project26/2/202517/6/2026
A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.
AplazadaAlta (7.1)0.15%—Mathieuhays Simple DocumentationAI13/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in mathieuhays Simple Documentation client-documentation allows Stored XSS.This issue affects Simple Documentation: from n/a through <= 1.2.8.
AnalizadaMedia (4.3)0.45%—Rankmath SEO13/2/202517/6/2026
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. This makes it possible for authenticated attackers, with Contributor-level access…