Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
3978 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'requestid' parameter in the endpoint '/ofrs/details.php'. | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'. | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'remark', 'status' and 'requestid' parameters in the endpoint '/ofrs/admin/request-details.php'. | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 17/6/2026 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'. | |
| Analizada | Media (5.1) | 0.21% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 30/9/2026 | XSS Almacenado en Online Fire Reporting System v1.2 de PHPGurukul, que consiste en un XSS autenticado reflejado y almacenado debido a la falta de validación adecuada de las entradas del usuario, el parámetro 'tname' vía GET y los parámetros 'teamleadname', 'teammember' y 'teamname' vía POST en el endpoint… | |
| Analizada | Crítica (9.3) | 0.33% | — | Phpgurukul Online Fire Reporting System | 11/9/2025 | 30/9/2026 | Inyección SQL en el Sistema de Informes de Incendios en Línea v1.2 de PHPGurukul. Esta vulnerabilidad permite a un atacante recuperar, crear, actualizar y eliminar la base de datos a través del parámetro 'teamid' en el endpoint '/ofrs/admin/edit-team.php'. | |
| Aplazada | Media (5.9) | 0.18% | — | Pixelines Email ProtectorAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixeline Pixeline's Email Protector pixelines-email-protector allows Stored XSS.This issue affects Pixeline's Email Protector: from n/a through <= 1.3.8. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Loan Management System | 8/9/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_payment. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and… | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Online Loan Management System | 8/9/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=delete_loan. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.48% | — | Carmelo Online Event Judging System | 8/9/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /review_search.php. The manipulation of the argument txtsearch leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Media (5.5) | 0.48% | — | Carmelo Online Event Judging System | 8/9/2025 | 17/6/2026 | A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the file /home.php. Executing manipulation of the argument main_event can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be… | |
| Analizada | Media (5.5) | 0.48% | — | Carmelo Online Event Judging System | 8/9/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function of the file /index.php. Performing manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the argument email leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Aplazada | Baja (2.3) | 0.11% | — | Ricoh Streamline NXAI | 8/9/2025 | 30/9/2026 | RICOH Streamline NX versiones 3.5.1 a 24R3 son vulnerables a la manipulación del historial de operaciones. Si un atacante puede realizar un ataque man-in-the-middle, podría alterar los valores de las solicitudes HTTP, lo que podría resultar en la manipulación del historial de operaciones de la herramienta de gestión… | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (5.5) | 0.41% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file /manage-profile.php. This manipulation of the argument email causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. | |
| Analizada | Baja (2) | 0.25% | — | Razormist Online Polling System | 8/9/2025 | 17/6/2026 | A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation of the argument firstname results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.42% | — | Emiloi Online Discussion Forum | 7/9/2025 | 30/9/2026 | Se ha encontrado un fallo en itsourcecode Online Discussion Forum 1.0. Esto afecta a una función desconocida del archivo /admin/admin_forum/add_views.PHP. La manipulación del argumento ID puede conducir a una inyección SQL. Es posible lanzar el ataque remotamente. El exploit ha sido publicado y puede ser utilizado. |