Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2773▼ 299 respecto a la semana anterior
Críticas / altas1298▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

3005 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.58%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+19/9/202517/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.58%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+19/9/202517/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.42%—Campcodes Online Loan Management System8/9/202517/6/2026
A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and…
AnalizadaMedia (5.5)0.48%—Campcodes Online Loan Management System8/9/202517/6/2026
A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_loan. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.48%—Carmelo Online Event Judging System8/9/202517/6/2026
A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /review_search.php. The manipulation of the argument txtsearch leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may…
AnalizadaMedia (5.5)0.48%—Carmelo Online Event Judging System8/9/202517/6/2026
A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the file /home.php. Executing manipulation of the argument main_event can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be…
AnalizadaMedia (5.5)0.48%—Carmelo Online Event Judging System8/9/202517/6/2026
A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function of the file /index.php. Performing manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and…
AnalizadaMedia (5.5)0.41%—Razormist Online Polling System8/9/202517/6/2026
A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the argument email leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.5)0.41%—Razormist Online Polling System8/9/202517/6/2026
A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
AnalizadaMedia (5.5)0.41%—Razormist Online Polling System8/9/202517/6/2026
A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
AnalizadaMedia (5.5)0.41%—Razormist Online Polling System8/9/202517/6/2026
A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file /manage-profile.php. This manipulation of the argument email causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
AnalizadaBaja (2)0.25%—Razormist Online Polling System8/9/202517/6/2026
A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation of the argument firstname results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and…
AnalizadaMedia (5.5)0.42%—Emiloi Online Discussion Forum7/9/202530/9/2026
Se ha encontrado un fallo en itsourcecode Online Discussion Forum 1.0. Esto afecta a una función desconocida del archivo /admin/admin_forum/add_views.PHP. La manipulación del argumento ID puede conducir a una inyección SQL. Es posible lanzar el ataque remotamente. El exploit ha sido publicado y puede ser utilizado.
AnalizadaMedia (5.5)0.43%—Emiloimagtolis Online Discussion Forum6/9/202517/6/2026
A vulnerability has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin. Such manipulation of the argument Username leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.5)0.42%—Phpgurukul Online Course Registration5/9/202517/6/2026
A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/semester.php. The manipulation of the argument semester leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.4)0.21%💥 PoCPhpgurukul Online Shopping Portal4/9/202517/6/2026
PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.
AnalizadaBaja (2)0.46%—Campcodes Online Recruitment Management System3/9/202517/6/2026
A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts the function include of the file /admin/index.php. The manipulation of the argument page results in file inclusion. It is possible to launch the attack remotely. The exploit has been released to the public and may be…
ModificadaCrítica (9.1)0.47%—Phpgurukul Online Shopping Portal3/9/202517/6/2026
phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.
AnalizadaMedia (5.5)0.42%—Donbermoy Online Farm Management System2/9/202517/6/2026
A vulnerability was detected in SourceCodester Online Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/login.php. Performing manipulation of the argument uname results in sql injection. It is possible to initiate the attack remotely. The exploit is now public…
AnalizadaMedia (5.5)0.48%—Fabian Online Hotel Reservation System1/9/202517/6/2026
A vulnerability was identified in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file /admin/edituser.php. The manipulation of the argument userid leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might…
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System1/9/202517/6/2026
A vulnerability was found in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /teacher_signup.php. Performing manipulation of the argument firstname results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. Other…
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System1/9/202517/6/2026
A vulnerability was detected in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /student_signup.php. The manipulation of the argument Username results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
AnalizadaMedia (5.5)0.42%—Campcodes Online Feeds Product Inventory System1/9/202517/6/2026
A security vulnerability has been detected in Campcodes Online Feeds Product Inventory System 1.0. This vulnerability affects unknown code of the file /feeds/index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been…
AnalizadaBaja (2)0.29%—Campcodes Online Hospital Management System1/9/202517/6/2026
A flaw has been found in Campcodes Online Hospital Management System 1.0. The impacted element is an unknown function of the file /edit-profile.php of the component Edit Profile Page. Executing manipulation of the argument Username can lead to cross site scripting. The attack may be launched remotely. The exploit has…
AnalizadaBaja (1.9)0.29%—Campcodes Online Hospital Management System1/9/202517/6/2026
A vulnerability was detected in Campcodes Online Hospital Management System 1.0. The affected element is an unknown function of the file /admin/patient-search.php of the component Patient Search Module. Performing manipulation of the argument Search by Name Mobile No results in cross site scripting. The attack may be…