Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

9817 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.57%💥 PoCThinkphp20/11/202517/6/2026
The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.
AnalizadaMedia (6.1)0.21%—Phppgadmin Project Phppgadmin20/11/202517/6/2026
phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by accepting user-controlled parameters ('subject', 'server', 'database', 'queryid') without proper validation or access control checks.…
AnalizadaMedia (6.5)0.29%—Phppgadmin Project Phppgadmin20/11/202517/6/2026
phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes user-controlled input from $_REQUEST['query'] directly to the browseQuery function without proper sanitization. An authenticated attacker can exploit this vulnerability to execute arbitrary SQL…
AnalizadaMedia (6.5)0.27%—Phppgadmin Project Phppgadmin20/11/202517/6/2026
phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['query'] parameter without any sanitization or parameterization via $data->conn->Execute($_REQUEST['query']). An authenticated attacker can…
AnalizadaMedia (6.1)0.23%—Phppgadmin Project Phppgadmin20/11/202517/6/2026
phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. User-supplied input from $_REQUEST parameters is reflected in HTML output without proper encoding or sanitization in multiple locations including sequences.php, indexes.php, admin.php, and other…
AnalizadaMedia (6.1)0.23%—Learnwithfair Php-ecommerce-project19/11/202517/6/2026
A reflected cross-site scripted (XSS) vulnerability in the /ecommerce/products.php component of E-commerce Project v1.0 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into the id parameter.
ModificadaMedia (6.9)0.20%—Mongodb C DriverMongodb PHP Driver18/11/20257/10/2026
Una mongoc_bulk_operation_t puede leer memoria no válida si se pasan opciones grandes.
AnalizadaAlta (7.5)0.23%—Phpgurukul Student Record System18/11/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS).
AnalizadaMedia (6.5)0.29%—HPE Arubaos-cx18/11/202517/6/2026
A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.
AnalizadaAlta (7.3)0.26%—HPE Arubaos-cx18/11/202517/6/2026
A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticated remote attacker to hijack an active user session. Successful exploitation may enable the attacker to maintain unauthorized access to the session, potentially leading to the view or modification of…
AnalizadaAlta (8.8)0.66%—HPE Arubaos-cx18/11/202517/6/2026
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.
AnalizadaAlta (8.8)0.66%—HPE Arubaos-cx18/11/202517/6/2026
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.
AnalizadaMedia (6.8)0.30%—HPE Arubaos-cx18/11/202517/6/2026
A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vulnerability could allow an attacker with administrative access to execute specific code that renders the switch non-bootable and effectively non-functional.
AnalizadaAlta (7.8)0.12%—HPE Arubaos-cx18/11/202517/6/2026
A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only users. If successfully exploited, this vulnerability could allow an attacker with read-only privileges to gain administrator access on the affected system.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.
AnalizadaMedia (5.4)0.22%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.
AnalizadaMedia (4.6)0.20%—Phpgurukul Complaint Management System17/11/202517/6/2026
PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Complaint Management System17/11/202517/6/2026
PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php.
AnalizadaMedia (6.1)0.22%—Phpgurukul Complaint Management System17/11/202517/6/2026
PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-search.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Complaint Management System17/11/202517/6/2026
PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the email and mobileno parameters in reset-password.php.
AnalizadaCrítica (9.8)0.41%—Phpgurukul Online Shopping Portal17/11/202528/9/2026
El Portal de Compras en Línea PHPGurukul 2.0 es vulnerable a inyección SQL a través del parámetro 'email' en forgot-password.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Complaint Management System17/11/202517/6/2026
PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the fromdate and todate parameters in between-date-userreport.php.